High severity8.1NVD Advisory· Published Feb 25, 2020· Updated Jun 17, 2026
CVE-2020-8819
CVE-2020-8819
Description
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cardgate/woocommercePackagist | < 3.1.16 | 3.1.16 |
Affected products
3- cpe:2.3:a:cardgate:cardgate_payments:*:*:*:*:*:woocommerce:*:*Range: <=3.1.15
- WooCommerce/CardGate Payments plugindescription
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/156504/WordPress-WooCommerce-CardGate-Payment-Gateway-3.1.15-Bypass.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/cardgate/woocommerce/blob/f2111af7b1a3fd701c1c5916137f3ac09482feeb/cardgate/cardgate.phpnvdExploitThird Party AdvisoryWEB
- github.com/cardgate/woocommerce/issues/18nvdExploitThird Party AdvisoryWEB
- www.exploit-db.com/exploits/48134nvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-5pq5-9phv-q5j3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8819ghsaADVISORY
- wpvulndb.com/vulnerabilities/10097nvdThird Party AdvisoryWEB
- github.com/cardgate/woocommerce/pull/17/commits/0b83588d604c8c56c7fded43144fcced96b2ada9ghsaWEB
News mentions
0No linked articles in our index yet.