Wordpress Alert: Webhook signature validation failures
An integration accepts incoming webhook data without verifying its signature. A forged notification may trigger order or account actions.
Guide tag · 12 matching pages
An integration accepts incoming webhook data without verifying its signature. A forged notification may trigger order or account actions.
An incoming webhook route trusts a request without authenticating its sender. External callers may trigger automation or data changes.
A product endpoint accepts edits from a user without catalog rights. Products may be sold at unintended prices.
A customer can change another customer's subscription identifier in a request. Billing or subscription settings may be altered across accounts.
A payment integration accepts an unverified completion signal. An unpaid order may appear paid or be fulfilled.
A customer can view or alter an order that is not theirs. Names, addresses, and purchase details may leak.
A pirated package contains hidden code or a modified updater. It may create a backdoor or steal data.
A gift-card extension trusts balance changes from an unauthorized request. Store credit may be created or spent improperly.
An API or plugin returns customer records to an unauthorized caller. Personal and purchase information may be exposed.
A low-privilege account can create or modify coupons. An attacker may issue discounts that the store never approved.
A checkout extension accepts files without suitable type or authorization checks. Customer-supplied files may become a code or data exposure route.
An extension trusts a client-submitted total instead of recalculating server-side. A buyer may be charged less than the actual order value.