CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-0692Public Exploit

BlueSnap Payment Gateway for WooCommerce - Missing Authorization (CVE-2026-0692)

PublishedFeb 14, 2026
First SeenN/A
Last Seen
Reported
CVSS7.5
wordpressecommercecms

Description

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's WC_Geolocation::get_ip_address() function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.

psychologyCrowdSec Analysis

CVE-2026-0692 is a high-severity missing authorization vulnerability in the BlueSnap Payment Gateway for WooCommerce plugin, affecting versions up to and including 3.4.0. Unauthenticated attackers can spoof trusted IP address headers to bypass allowlist protections and submit forged payment notifications, potentially manipulating WooCommerce order statuses as paid, failed, refunded, or on-hold.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-0692 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target the WordPress WooCommerce BlueSnap IPN webhook at /?wc-api=bluesnap using unauthenticated POST requests. Exploitation attempts may spoof the X-Forwarded-For header and submit form data containing transactionType=CHARGEBACK, a fabricated merchantTransactionId, and related transaction fields to bypass webhook authorization and manipulate order statuses.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-02-14
Rule Released2026-10-05

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.