{
 "id": "WPSEC-2026-0557",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0557/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0557/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0557/index.md",
 "title": "Asaas Gateway for WooCommerce <= 2.7.7 - Improper Webhook Authentication to Unauthenticated Order Status Manipulation",
 "description": "The Asaas Gateway for WooCommerce plugin for WordPress is vulnerable to improper authentication in its webhook endpoint in all versions up to, and including, 2.7.7. When no webhook token is stored in the gateway settings, a request without a token passes the check, and the endpoint then updates the order named in the request after only confirming with Asaas that the referenced payment exists and has the stated status. This makes it possible for unauthenticated attackers to forge payment events that mark unpaid orders as paid or set orders to failed, pending or cancelled. Only stores without a stored webhook token are affected, mainly stores whose webhook was set up in older versions, where the token was optional.",
 "plugin": {
  "slug": "woo-asaas",
  "name": "Asaas Gateway for WooCommerce",
  "full_name": "Asaas Gateway for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woo-asaas/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woo-asaas/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woo-asaas"
 },
 "type": "AUTH",
 "cwe": [
  "CWE-287"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.7.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.7.8"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.7.8",
 "remediation": "Update to 2.7.8 or later.",
 "fix_released": "2026-10-05T17:08:42+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-07T15:30:54.748892+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0557/",
  "https://plugins.svn.wordpress.org/woo-asaas/tags/2.7.8/",
  "https://wordpress.org/plugins/woo-asaas/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woo-asaas",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}