CVE-2026-0692

T

he BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.

Configurations

No configuration.

History

14 Feb 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-14 05:16

Updated : 2026-02-18 17:52


NVD link : CVE-2026-0692

Mitre link : CVE-2026-0692

CVE.ORG link : CVE-2026-0692


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization