CVE-2025-14078

T

he PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on the paygent_check_webhook function combined with the paygent_permission_callback function unconditionally returning true on line 199. This makes it possible for unauthenticated attackers to manipulate payment callbacks and modify order statuses by sending forged payment notifications via the `/wp-json/paygent/v1/check/` endpoint.

Configurations

No configuration.

History

17 Jan 2026, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-17 09:15

Updated : 2026-01-26 15:05


NVD link : CVE-2025-14078

Mitre link : CVE-2025-14078

CVE.ORG link : CVE-2025-14078


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization