PatchSiren cyber security CVE debrief
CVE-2026-15205 Paymob CVE debrief
The Paymob for WooCommerce WordPress plugin before 4.1.9 is vulnerable to SQL injection attacks due to improper sanitization of client-supplied identifiers in its public, unauthenticated payment callback. This vulnerability allows unauthenticated attackers to read arbitrary data from the database, including user credentials and other secrets. The plugin performs SQL queries before verifying the payment provider's HMAC signature, further increasing the risk of exploitation. Organizations should verify their deployments and prioritize updates. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Vendor
- Paymob
- Product
- Paymob for WooCommerce
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-14
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-14
- Advisory updated
- 2026-08-26
Who should care
Organizations using the Paymob for WooCommerce WordPress plugin, especially those with high-security requirements, should prioritize updating to version 4.1.9 or later to mitigate SQL injection attacks. Additionally, organizations with exposed systems should review compensating controls and verify payment provider HMAC signatures before performing SQL queries. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. IT teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Technical summary
The Paymob for WooCommerce WordPress plugin before 4.1.9 is vulnerable to SQL injection attacks due to improper sanitization of client-supplied identifiers in its public payment callback. This vulnerability allows unauthenticated attackers to read arbitrary data from the database, including user credentials and other secrets. The plugin performs SQL queries before verifying the payment provider's HMAC signature, further increasing the risk of exploitation.
Defensive priority
Organizations using the Paymob for WooCommerce WordPress plugin should prioritize updating to version 4.1.9 or later to mitigate SQL injection attacks.
Recommended defensive actions
- Update Paymob for WooCommerce WordPress plugin to version 4.1.9 or later
- Verify payment provider's HMAC signature before performing SQL queries
- Implement additional security measures to prevent SQL injection attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based blind extraction. The vulnerability has been publicly disclosed and may be exploited by attackers to gain unauthorized access to sensitive information. Organizations should verify their deployments and prioritize updates.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15205 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15205
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15205 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15205
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/cbde48bb-5aa4-4f69-8101-095132239923/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.