What is CVE-2026-15205?
CVE-2026-15205 is an SQL Injection vulnerability in the 'Paymob for WooCommerce' WordPress plugin (before version 4.1.9). An unsanitized client-supplied identifier is used in a SQL query via an unauthenticated payment callback before HMAC signature verification. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-15205, "Paymob for WooCommerce" WordPress plaginində (4.1.9-dan əvvəlki versiyalarda) SQL injection zəifliyidir. Təhlükəsizlik yoxlaması aparılmamış müştəri identifikatoru ictimai, autentifikasiya tələb olunmayan ödəniş callback funksiyasında istifadə olunur. Plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What plugin is affected by CVE-2026-15205?
This vulnerability affects the 'Paymob for WooCommerce' WordPress plugin.
What should be done to protect against CVE-2026-15205?
It is recommended to update the plugin to version 4.1.9 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.