---
id: CVE-2026-87978
title: >-
  The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the
  request signature on one branch of its payment webhook, allowing
  unauthenticated attackers to mark arbitrary WooCommerce orders as paid without
  any payment.
summary: >-
  The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the
  request signature on one branch of its payment webhook, allowing
  unauthenticated attackers to mark arbitrary WooCommerce orders as paid without
  any payment.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-345
product: Paymob for WooCommerce
affected:
  - paymob_for_woocommerce < 4.1.14
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87978'
references:
  - url: 'https://wpscan.com/vulnerability/7eecf65a-3b85-405e-bbe2-893960c82ba7/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-23T10:34:41.598724Z'
ingestedAt: '2026-09-23T10:21:54.379Z'
epss: 0.00114
epssPercentile: 0.01352
---

## Overview

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
