The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made.
Metrics
Affected Vendors & Products
References
History
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phonepe
Phonepe phonepe Payment Solutions Wordpress Wordpress wordpress |
|
| Vendors & Products |
Phonepe
Phonepe phonepe Payment Solutions Wordpress Wordpress wordpress |
Fri, 17 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Fri, 17 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a payment-success notification and mark unpaid WooCommerce orders as paid without any payment being made. | |
| Title | PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-07-17T06:00:01.861Z
Updated: 2026-07-17T13:03:16.958Z
Reserved: 2026-06-08T11:16:29.712Z
Link: CVE-2026-11575
Updated: 2026-07-17T13:01:13.304Z
No data.
No data.