CVE-2026-15205Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based blind extraction.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-14: 2Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 208-14
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-15205 The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, una… https://www.cve.org/CVERecord?id=CVE-2026-15205

    Post summary

    The CVE describes a SQL injection flaw in the Paymob for WooCommerce WordPress plugin caused by insufficient input sanitisation; no exploitation evidence, PoC, or patch information is provided.

    000201.0K
    58.1K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    Businesses using Paymob for WooCommerce should update to 4.1.9+. CVSS 8.6 vulnerability in unauthenticated payment callback. https://nvd.nist.gov/vuln/detail/CVE-2026-15205 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/sRRCt8mRF4

    Post summary

    The post urges WooCommerce users of Paymob to upgrade to version 4.1.9+ to mitigate a high‑severity (CVSS 8.6) unauthenticated payment callback vulnerability (CVE-2026-15205).

    0000044
    92 followersView on X

Explore more