OnPay.io for WooCommerce <= 1.0.53 - Cross-Site Request Forgery via OAuth Callback
- ID
- WPSEC-2026-0576
- Plugin
- OnPay.io for WooCommerce (onpay-io-for-woocommerce)
- Affected
- all versions before 1.0.54
- Remediation
- Update to 1.0.54 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- Weakness
- CWE-352
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- OnPay.io for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The OnPay.io for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.53. This is due to missing OAuth state validation and PKCE in the OAuth callback handler on the plugin's settings page, which exchanges any supplied authorization code. This makes it possible for unauthenticated attackers to connect the store to an OnPay account they control, replacing the store's gateway ID and secret so that customer payments are processed through the attacker's account, via a forged request granted they can trick a site administrator into visiting a crafted link while the store is not connected to OnPay.
References
- https://wpsec.com/vuln/WPSEC-2026-0576/
- https://plugins.svn.wordpress.org/onpay-io-for-woocommerce/tags/1.0.54/
- https://wordpress.org/plugins/onpay-io-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS