he BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.
No configuration.
14 Feb 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-02-14 05:16
Updated : 2026-02-18 17:52
NVD link : CVE-2026-0692
Mitre link : CVE-2026-0692
CVE.ORG link : CVE-2026-0692
JSON object : View
No product.
Missing Authorization