CVE-2026-92430: CWE-862 Missing Authorization in Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before version 5.4.7 contains a missing authorization vulnerability. It fails to verify the authenticity of PIX payment webhooks before updating order statuses. This flaw allows unauthenticated attackers to mark pending orders as paid without actually completing payment.
AI Analysis
Technical Summary
CVE-2026-92430 is a missing authorization vulnerability (CWE-862) in the Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress. Versions from 3.6.1 up to but not including 5.4.7 do not authenticate incoming PIX payment webhooks, enabling attackers to spoof payment notifications and update order statuses to paid without legitimate transactions.
Potential Impact
An attacker can fraudulently mark orders as paid, potentially bypassing payment controls and causing financial loss or order fulfillment without actual payment.
Mitigation Recommendations
Upgrade the Rede Itaú for WooCommerce plugin to version 5.4.7 or later where this vulnerability is fixed. No other mitigation guidance is provided. Patch status is not explicitly stated but the version range indicates the issue is fixed starting at 5.4.7.
CVE-2026-92430: CWE-862 Missing Authorization in Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
Description
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before version 5.4.7 contains a missing authorization vulnerability. It fails to verify the authenticity of PIX payment webhooks before updating order statuses. This flaw allows unauthenticated attackers to mark pending orders as paid without actually completing payment.
Affected software
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92430 is a missing authorization vulnerability (CWE-862) in the Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress. Versions from 3.6.1 up to but not including 5.4.7 do not authenticate incoming PIX payment webhooks, enabling attackers to spoof payment notifications and update order statuses to paid without legitimate transactions.
Potential Impact
An attacker can fraudulently mark orders as paid, potentially bypassing payment controls and causing financial loss or order fulfillment without actual payment.
Mitigation Recommendations
Upgrade the Rede Itaú for WooCommerce plugin to version 5.4.7 or later where this vulnerability is fixed. No other mitigation guidance is provided. Patch status is not explicitly stated but the version range indicates the issue is fixed starting at 5.4.7.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-16T10:08:51.566Z
- State
- PUBLISHED
Threat ID: 6aae2c6955bf5e2cf5363ae3
Added to database: 09/19/2026, 06:32:09 UTC
Last enriched: 09/19/2026, 06:46:31 UTC
Last updated: 09/19/2026, 06:46:31 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.