# Asaas Gateway for WooCommerce <= 2.7.7 - Improper Webhook Authentication to Unauthenticated Order Status Manipulation

- **ID:** WPSEC-2026-0557
- **Plugin:** Asaas Gateway for WooCommerce (`woo-asaas`), https://wordpress.org/plugins/woo-asaas/
- **Affected versions:** all versions before 2.7.8
- **Fixed in:** 2.7.8 (Update to 2.7.8 or later.)
- **Severity:** Medium 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woo-asaas
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0557/

## Description

The Asaas Gateway for WooCommerce plugin for WordPress is vulnerable to improper authentication in its webhook endpoint in all versions up to, and including, 2.7.7. When no webhook token is stored in the gateway settings, a request without a token passes the check, and the endpoint then updates the order named in the request after only confirming with Asaas that the referenced payment exists and has the stated status. This makes it possible for unauthenticated attackers to forge payment events that mark unpaid orders as paid or set orders to failed, pending or cancelled. Only stores without a stored webhook token are affected, mainly stores whose webhook was set up in older versions, where the token was optional.

## References

- https://wpsec.com/vuln/WPSEC-2026-0557/
- https://plugins.svn.wordpress.org/woo-asaas/tags/2.7.8/
- https://wordpress.org/plugins/woo-asaas/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0557/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
