CVE-2026-3208Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code images for arbitrary orders. PIX QR codes contain sensitive merchant information including PIX keys (which may be CPF/CNPJ personal identifiers), transaction amounts, merchant name and city, and MercadoPago transaction references.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-06: 3Technical Details · 2026-05-06: 205-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3208 The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooC… https://www.cve.org/CVERecord?id=CVE-2026-3208

    Post summary

    A missing capability check in the Mercado Pago WooCommerce plugin allows unauthorized data access (CVE-2026-3208). No PoC, exploit, or patch information is provided.

    00020280
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3208 Unauthenticated Data Access in Mercado Pago WooCommerce Pl... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3208 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet links to a vulnerability detail page for CVE‑2026‑3208 and promotes vulnerability scanning, but provides no additional technical or exploit information.

    0000052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3208 The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooC… https://www.cve.org/CVERecord?id=CVE-2026-3208 ----- Traducción: CVE-2026-3208 Los… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-3208, noting that the Mercado Pago WooCommerce plugin lacks a capability check, allowing unauthorized data access. No exploitation details, patch information, or PoC are provided.

    0000062
    75 followersView on X

Explore more