# OnPay.io for WooCommerce <= 1.0.53 - Cross-Site Request Forgery via OAuth Callback

- **ID:** WPSEC-2026-0576
- **Plugin:** OnPay.io for WooCommerce (`onpay-io-for-woocommerce`), https://wordpress.org/plugins/onpay-io-for-woocommerce/
- **Affected versions:** all versions before 1.0.54
- **Fixed in:** 1.0.54 (Update to 1.0.54 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)
- **Weakness:** CWE-352
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/onpay-io-for-woocommerce
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0576/

## Description

The OnPay.io for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.53. This is due to missing OAuth state validation and PKCE in the OAuth callback handler on the plugin's settings page, which exchanges any supplied authorization code. This makes it possible for unauthenticated attackers to connect the store to an OnPay account they control, replacing the store's gateway ID and secret so that customer payments are processed through the attacker's account, via a forged request granted they can trick a site administrator into visiting a crafted link while the store is not connected to OnPay.

## References

- https://wpsec.com/vuln/WPSEC-2026-0576/
- https://plugins.svn.wordpress.org/onpay-io-for-woocommerce/tags/1.0.54/
- https://wordpress.org/plugins/onpay-io-for-woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0576/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
