Asaas Gateway for WooCommerce <= 2.7.7 - Improper Webhook Authentication to Unauthenticated Order Status Manipulation

Medium 5.9 CWE-287Fixed in 2.7.8
ID
WPSEC-2026-0557
Plugin
Asaas Gateway for WooCommerce (woo-asaas)
Affected
all versions before 2.7.8
Remediation
Update to 2.7.8 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-287
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Asaas Gateway for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Asaas Gateway for WooCommerce plugin for WordPress is vulnerable to improper authentication in its webhook endpoint in all versions up to, and including, 2.7.7. When no webhook token is stored in the gateway settings, a request without a token passes the check, and the endpoint then updates the order named in the request after only confirming with Asaas that the referenced payment exists and has the stated status. This makes it possible for unauthenticated attackers to forge payment events that mark unpaid orders as paid or set orders to failed, pending or cancelled. Only stores without a stored webhook token are affected, mainly stores whose webhook was set up in older versions, where the token was optional.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0