Asaas Gateway for WooCommerce <= 2.7.7 - Improper Webhook Authentication to Unauthenticated Order Status Manipulation
- ID
- WPSEC-2026-0557
- Plugin
- Asaas Gateway for WooCommerce (woo-asaas)
- Affected
- all versions before 2.7.8
- Remediation
- Update to 2.7.8 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Weakness
- CWE-287
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Asaas Gateway for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Asaas Gateway for WooCommerce plugin for WordPress is vulnerable to improper authentication in its webhook endpoint in all versions up to, and including, 2.7.7. When no webhook token is stored in the gateway settings, a request without a token passes the check, and the endpoint then updates the order named in the request after only confirming with Asaas that the referenced payment exists and has the stated status. This makes it possible for unauthenticated attackers to forge payment events that mark unpaid orders as paid or set orders to failed, pending or cancelled. Only stores without a stored webhook token are affected, mainly stores whose webhook was set up in older versions, where the token was optional.
References
- https://wpsec.com/vuln/WPSEC-2026-0557/
- https://plugins.svn.wordpress.org/woo-asaas/tags/2.7.8/
- https://wordpress.org/plugins/woo-asaas/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS