PAYGENT for WooCommerce Missing Authorization Vulnerability in Payment Callback Handling

Vulnerability

A missing authorization vulnerability has been identified in the PAYGENT for WooCommerce plugin for WordPress, affecting all versions through 2.4.6. The issue arises from inadequate authorization checks in the 'paygent_check_webhook' function, coupled with the 'paygent_permission_callback' function always returning true. This flaw allows unauthenticated attackers to interfere with payment callbacks and alter order statuses by sending fake payment notifications via the '/wp-json/paygent/v1/check/' endpoint.

Impact

Exploitation of this vulnerability allows for unauthorized manipulation of payment callbacks and order statuses within WooCommerce.

Remediation

Users can update to version 2.4.7 or a newer patched version to address this vulnerability.

Added: Jan 17, 2026, 9:25 AM
Updated: Jan 17, 2026, 9:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.7
remediation
0.0
relevance
2.1
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.