PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40741 Jose Conti CVE debrief

CVE-2026-40741 is a HIGH severity vulnerability in Redsys for WooCommerce Light plugin versions <= 7.0.0. The vulnerability is caused by Unauthenticated Broken Access Control. The CVSS score is 7.5.

Vendor
Jose Conti
Product
Redsys for WooCommerce Light
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of Redsys for WooCommerce Light plugin versions <= 7.0.0 should update to a patched version to prevent exploitation.

Technical summary

The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N and is classified under CWE-862.

Defensive priority

HIGH

Recommended defensive actions

  • Update Redsys for WooCommerce Light plugin to a version greater than 7.0.0.
  • Review and apply patches provided by the vendor.

Evidence notes

Evidence from Patchstack indicates that the vulnerability exists in Redsys for WooCommerce Light plugin versions <= 7.0.0.

Official resources

CVE-2026-40741 was published on 2026-06-15T21:16:48.883Z and modified on 2026-06-15T21:24:32.790Z.