CVE-2026-92430

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-21: 109-21
Full discourse1 post
  • Laprovittera Carlos@laprovittera

    Un atacante sin credenciales podía marcar órdenes como pagas en tiendas WooCommerce sin transferir un solo peso. CVE-2026-92430, plugin Rede Itaú for WooCommerce, versiones anteriores a la 5.4.7. 🧵 https://t.co/yM45k11pHg

    13041526
    13.4K followersView on X

Explore more