Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-9027— CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint

Quick assessment

Affected
corvusinfo CorvusPay WooCommerce Payment Gateway
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress CorvusPay WooCommerce Payment Gateway是WordPress基金会的一款灵活、高度可靠且高可用性的互联网支付网关服务。 WordPress CorvusPay WooCommerce Payment Gateway 2.7.4及之前版本存在加密问题漏洞,该漏洞源于密码签名验证不当,可能导致未经身份验证的攻击者通过发送包含任意或伪造签名的POST请求至success端点,将任何待处理的WooCommerce订单标记为已全额付款,从而无需付款即可获取商品或

CVSS 5.3 · Medium EPSS 0.37% · P28

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
corvusinfo CorvusPay WooCommerce Payment Gateway ≤ 2.7.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9027

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` with `'permission_callback' => '__return_true'`, and while it calls `$this->client->validate->signature()` and stores the boolean result in `$res`, the result is never evaluated in a conditional — it is only written to the debug log — causing execution to unconditionally reach `$order->payment_complete()` regardless of whether the cryptographic signature is valid. This makes it possible for unauthenticated attackers to mark any pending WooCommerce order as fully paid by sending a POST request to the success endpoint containing an arbitrary or forged signature value, allowing them to obtain goods or services without payment. Because WooCommerce order IDs are sequential integers, target orders are trivially enumerable via the `order_number` POST parameter, requiring no prior knowledge of the victim order.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress CorvusPay WooCommerce Payment Gateway 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress CorvusPay WooCommerce Payment Gateway是WordPress基金会的一款灵活、高度可靠且高可用性的互联网支付网关服务。 WordPress CorvusPay WooCommerce Payment Gateway 2.7.4及之前版本存在加密问题漏洞,该漏洞源于密码签名验证不当,可能导致未经身份验证的攻击者通过发送包含任意或伪造签名的POST请求至success端点,将任何待处理的WooCommerce订单标记为已全额付款,从而无需付款即可获取商品或
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
corvusinfo CorvusPay WooCommerce Payment Gateway 0 ~ 2.7.4 -

II. Public POCs for CVE-2026-9027

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9027

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-9027 (1)

News Coverage for CVE-2026-9027 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9027

No comments yet


Leave a comment