Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-16947: WooCommerce payment plugin can expose credentials and fake payments

CVE-2026-16947 · published 5 days ago
Summary

The Total Payments plugin for WooCommerce (up to version 7.3) lets a remote user tell the system to contact any web address and does not check that the reply is genuine. This can leak the store's payment‑gateway login details and allow attackers to mark any order as already paid. Update the plugin to the latest version or apply the vendor's patch, and restrict outbound connections from your web server.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown total processing card payments for woocommerce <= 7.3
Original advisory text
Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success response that marks arbitrary WooCommerce orders as paid.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-16947 · MITRE
Monitor software like this
Free during beta