BlueSnap Payment Gateway for WooCommerce - Missing Authorization (CVE-2026-0692)
Description
The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's WC_Geolocation::get_ip_address() function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.
psychologyCrowdSec Analysis
CVE-2026-0692 is a high-severity missing authorization vulnerability in the BlueSnap Payment Gateway for WooCommerce plugin, affecting versions up to and including 3.4.0. Unauthenticated attackers can spoof trusted IP address headers to bypass allowlist protections and submit forged payment notifications, potentially manipulating WooCommerce order statuses as paid, failed, refunded, or on-hold.
CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-0692 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers target the WordPress WooCommerce BlueSnap IPN webhook at /?wc-api=bluesnap using unauthenticated POST requests. Exploitation attempts may spoof the X-Forwarded-For header and submit form data containing transactionType=CHARGEBACK, a fabricated merchantTransactionId, and related transaction fields to bypass webhook authorization and manipulate order statuses.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-02-14 |
| Rule Released | 2026-10-05 |