CVE-2026-16947: Manipulable WooCommerce Payment Status
This text was generated using artificial intelligence (AI).On August 29, 2026, CVE-2026-16947 for the WordPress plugin Total Card Payments Processed for WooCommerce Published. Affected versions include those up to and including 7.3.
The vulnerability affects the server-side verification of payment transactions. The plugin does not validate a path provided by the user before generating a server-side verification request. Furthermore, it does not verify the authenticity of the received response.
WPScan assigns CVE-2026-16947 a CVSS 3.1 score of 9.1. The vulnerability can be exploited without prior authentication and without any user interaction.
There are three possible outcomes:
Server-side verification requests can be redirected to any host.
The merchant's payment gateway credentials may be disclosed in the process.
A fake success response can mark any WooCommerce order as paid.
The vulnerability thus combines risks to the confidentiality of gateway access credentials with risks to the integrity of payment and order data.
A breach involving the disclosure of payment gateway credentials may constitute a reportable data breach under Article 33 of the GDPR, for which there is a 72-hour deadline for reporting to the competent supervisory authority. For organizations subject to NIS 2 in Germany and Austria—as implemented through the respective national implementing legislation—there is an additional obligation to immediately report security-related incidents. Swiss online store operators must report such incidents to the Federal Office for Cybersecurity (BACS) in accordance with the revised Information Security Act (ISG).
Why Payment Verification Is Affected
The plugin uses a user-controlled path when constructing a server-side request for payment verification. Without validation, an attacker could redirect the request to any destination.
According to WPScan, the response to this request is not verified for authenticity. As a result, a tampered successful response could enter the payment process and mark the status of a WooCommerce order as paid.
For online stores, this particularly affects processes that trigger shipping, accounting, or customer service based on payment status. An order marked as paid may be based on an inauthentic verification response.
Measures for Affected Stores
As of the time of this publication, no official patch is available. Therefore, disabling the plugin is the primary mitigation measure until an update from the vendor becomes available.
As a temporary measure until an update becomes available, you might consider the following:
Restrict the web server's outbound HTTP traffic to known payment gateway endpoints.
Limiting outbound HTTP traffic restricts the ability to redirect server-side verification requests to arbitrary hosts. It does not replace updating the plugin.
In addition, affected organizations should prioritize the following audits:
Payment gateway credentials, such as API keys and merchant credentials, are rotated if the plugin has been installed.
Check the WooCommerce order history for unauthorized changes to the „paid“ status.
Prioritize and mitigate affected systems based on their payment functions.
Maintain an inventory of the WordPress plugins in use.
Enable automatic updates for security-related plugins as soon as a patch becomes available.
Classify Externally Visible Stores
For CVE-2026-16947, the external visibility of the affected e-commerce infrastructure is relevant for prioritization. WordPress installations and active plugins can be identified via HTTP fingerprinting, for example through plugin paths or version metadata in the HTML.
As part of external attack surface management, LocateRisk helps identify publicly accessible web applications under customer domains and assign visible WordPress installations or plugins for review. This helps teams determine which externally accessible online stores should be checked for use of the affected plugin.
An external assessment does not replace a review of the patch status. LocateRisk does not necessarily identify the specific vulnerable plugin version. However, the technical visibility of e-commerce systems can help structure the review of payment functionality, components in use, responsibilities, and potentially affected gateway credentials.
Am I affected?
This affects "Total Processing Card Payments for WooCommerce" in the versions listed above. If you want to know whether "Total Processing Card Payments for WooCommerce" is even visible in your own externally accessible infrastructure, you can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
As of the date this vulnerability was disclosed on August 29, 2026, no official patch is available. Administrators should disable the plugin until the vendor releases an update and regularly monitor the patch status via the WPScan Advisory.
The plugin should be disabled immediately. In addition, it is recommended to rotate all payment gateway credentials, such as API keys and merchant credentials, and to check the order history for unauthorized status changes. Outgoing HTTP traffic from the web server should be restricted to known payment gateway endpoints.
As of August 31, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.