PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107420 Narinder Singh CVE debrief

CVE-2026-107420 is a vulnerability in the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin, version <= 1.7.2. The vulnerability allows for an unauthenticated bypass, potentially leading to unauthorized access or disruption of payment processing. Defenders should assess exposure and prioritize remediation, particularly in environments where the plugin is used. The CVSS score is 5.3, with a severity of MEDIUM. This vulnerability was reported by an external source and verified through CVE and NVD records.

Vendor
Narinder Singh
Product
Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for managing the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin should assess exposure and prioritize remediation.

Why it matters

CVE-2026-107420 is a medium-severity vulnerability in the Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, particularly in environments where the plugin is used.

  • Potential unauthorized access to sensitive data
  • Possible disruption of payment processing
  • Need for verification of plugin presence and exposure
  • Prioritization of remediation efforts

Technical summary

The Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin, version <= 1.7.2, is vulnerable to an unauthenticated bypass. This vulnerability could allow attackers to bypass authentication mechanisms, potentially leading to unauthorized access or disruption of payment processing. The CVSS score is 5.3, with a severity of MEDIUM. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, particularly in environments where the plugin is used.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, particularly in environments where the plugin is used.

Recommended defensive actions

  • Verify the presence of the vulnerable plugin in your inventory
  • Assess exposure and prioritize remediation
  • Monitor for potential unauthorized access

Evidence notes

The vulnerability details are based on the CVE and NVD records. However, the limited information available does not provide specific details on exploitation or impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107420 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107420

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107420 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107420

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.