OnPay.io for WooCommerce <= 1.0.53 - Cross-Site Request Forgery via OAuth Callback

Medium 5.3 CWE-352Fixed in 1.0.54
ID
WPSEC-2026-0576
Plugin
OnPay.io for WooCommerce (onpay-io-for-woocommerce)
Affected
all versions before 1.0.54
Remediation
Update to 1.0.54 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness
CWE-352
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
OnPay.io for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The OnPay.io for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.53. This is due to missing OAuth state validation and PKCE in the OAuth callback handler on the plugin's settings page, which exchanges any supplied authorization code. This makes it possible for unauthenticated attackers to connect the store to an OnPay account they control, replacing the store's gateway ID and secret so that customer payments are processed through the attacker's account, via a forged request granted they can trick a site administrator into visiting a crafted link while the store is not connected to OnPay.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0