# CVE-2026-0692: BlueSnap Payment Gateway for WooCommerce - Missing Authorization

> Live exploitation tracking for CVE-2026-0692 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-0692

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 7.5
- **Public exploit available:** Yes
- **Affected products:** BlueSnap Payment Gateway for WooCommerce
- **Weaknesses:** CWE-862 (Missing Authorization)
- **Tags:** wordpress, ecommerce, cms

## Description

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.

## CrowdSec analysis

[CVE-2026-0692](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-0692) is a high-severity missing authorization vulnerability in the BlueSnap Payment Gateway for WooCommerce plugin, affecting versions up to and including 3.4.0. Unauthenticated attackers can spoof trusted IP address headers to bypass allowlist protections and submit forged payment notifications, potentially manipulating WooCommerce order statuses as paid, failed, refunded, or on-hold.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-0692 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target the WordPress WooCommerce BlueSnap IPN webhook at `/?wc-api=bluesnap` using unauthenticated POST requests. Exploitation attempts may spoof the `X-Forwarded-For` header and submit form data containing `transactionType=CHARGEBACK`, a fabricated `merchantTransactionId`, and related transaction fields to bypass webhook authorization and manipulate order statuses.

## Timeline

- 2026-02-14: CVE Published. CVE-2026-0692 is published to NVD.
- 2026-10-05: Rule Released. CrowdSec releases a rule to detect CVE-2026-0692 exploitation attempts against the CrowdSec Network.
- 2026-10-07: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-0692 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0692.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-0692) follows observed exploitation activity for CVE-2026-0692. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
