PatchSiren

Paymob CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Paymob CVE published 2026-08-14

CVE-2026-15205

The Paymob for WooCommerce WordPress plugin before 4.1.9 is vulnerable to SQL injection attacks due to improper sanitization of client-supplied identifiers in its public, unauthenticated payment callback. This vulnerability allows unauthenticated attackers to read arbitrary data from the database, including user credentials and other secrets. The plugin performs SQL queries before verifying the payment pr [truncated]