What is CVE-2026-12584?
CVE-2026-12584 is a vulnerability in the 'Payment Gateway for Redsys & WooCommerce Lite' WordPress plugin versions before 7.0.2. It fails to verify the authenticity of incoming payment notifications, allowing unauthenticated attackers to forge payment confirmations and mark orders as paid. Updating to the latest plugin version is strongly recommended.
Azərbaycanca: CVE-2026-12584 zəifliyi 'Payment Gateway for Redsys & WooCommerce Lite' WordPress plagininin 7.0.2-dən əvvəlki versiyalarında aşkarlanıb. Bu zəiflik autentifikasiya olunmamış hücumçulara saxta ödəniş təsdiqi göndərərək sifarişləri ödənilmiş kimi qeyd etməyə imkan verir, çünki plagin ödəniş bildirişlərinin doğruluğunu yoxlamır. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which WordPress plugin users are affected by the CVE-2026-12584 vulnerability?
This vulnerability affects the 'Payment Gateway for Redsys & WooCommerce Lite' plugin versions before 7.0.2.
What should be done to protect against CVE-2026-12584?
It is recommended to update the plugin to the latest version (7.0.2 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.