CVE-2026-5050Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 7.0.0 due to successful_request() handlers calculating a local signature but not validating Ds_Signature from the request before accepting payment status across the Redsys, Bizum, and Google Pay gateway flows. This makes it possible for unauthenticated attackers to forge payment callback data and mark pending orders as paid when they know a valid order key and order amount, potentially allowing checkout completion and product or service fulfillment without a successful payment.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-16: 3Technical Details · 2026-04-16: 304-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5050 Improper Cryptographic Signature Verification in Payment Gateway for Redsys & WooCommerce Lite https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5050

    Post summary

    The post references CVE-2026-5050 as an improper cryptographic signature verification flaw in Redsys & WooCommerce Lite, but offers no further details such as PoC, exploitation or patch information.

    0000096
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5050 The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and includin… https://www.cve.org/CVERecord?id=CVE-2026-5050

    Post summary

    The passage announces CVE‑2026‑5050, a vulnerability in the Redsys & WooCommerce Lite plugin identified as an improper verification of a cryptographic signature, without providing proof of exploitation, tools, or remediation.

    00000112
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5050 The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Crypto… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5050 #WordPress #CyberSecurity #InfoSec

    Post summary

    A new vulnerability (CVE‑2026‑5050) affecting the Redsys and WooCommerce Lite plugins has been disclosed, noting improper cryptographic verification and a CVSS score of 7.5, with no PoC, exploit, or patch details provided.

    000005
    145 followersView on X

Explore more