Pay With MetaMask For WooCommerce <= 1.7.2 - Unauthenticated Payment Verification Bypass via Forged ERC-20 Token Transfer

High 7.5 CWE-345Fixed in 1.7.3
ID
WPSEC-2026-0747
Plugin
Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway (cryptocurrency-payments-using-metamask-for-woocommerce)
Affected
all versions before 1.7.3
Remediation
Update to 1.7.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-345
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
Pay With MetaMask For WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Pay With MetaMask For WooCommerce plugin for WordPress is vulnerable to payment verification bypass via the transaction verification REST endpoint in all versions up to, and including, 1.7.2. This is due to insufficient verification of on-chain transaction data. When any transaction carried calldata in the form of an ERC-20 transfer(address,uint256) call, the plugin read the recipient and amount from that calldata and accepted the payment. It did not check that the transaction was sent to the order's token contract, that a matching Transfer event was emitted, or that the order was meant to be paid in a token at all. This makes it possible for unauthenticated attackers (customers using guest checkout) to mark their own WooCommerce orders as paid without paying. They only need to submit a successful zero-value transaction that carries crafted transfer calldata naming the merchant wallet and the order amount, sent to an address or contract they control.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0