PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40741 Jose Conti CVE debrief

CVE-2026-40741 is a HIGH severity vulnerability in Redsys for WooCommerce Light plugin versions <= 7.0.0. The vulnerability is caused by Unauthenticated Broken Access Control. The CVSS score is 7.5.

Vendor
Jose Conti
Product
Redsys for WooCommerce Light
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of Redsys for WooCommerce Light plugin versions <= 7.0.0 should update to a patched version to prevent exploitation.

Technical summary

The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N and is classified under CWE-862.

Defensive priority

HIGH

Recommended defensive actions

  • Update Redsys for WooCommerce Light plugin to a version greater than 7.0.0.
  • Review and apply patches provided by the vendor.

Evidence notes

Evidence from Patchstack indicates that the vulnerability exists in Redsys for WooCommerce Light plugin versions <= 7.0.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40741 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40741

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40741 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40741

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.