VYPR

Paymob for WooCommerce

by WordPress

CVEs (3)

  • CVE-2026-15205HigAug 14, 2026
    risk 0.56cvss 8.6epss 0.00

    The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature.…

  • CVE-2026-66611HigAug 20, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.

  • CVE-2026-56025HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.