Skip to content
Latest alertUnauthenticated security-check bypass in Pay With MetaMask for WooCommerce plugin up to 1.7.2
0xCERT
All advisories
Medium0xCERT-2026-0233·

Unauthenticated security-check bypass in Pay With MetaMask for WooCommerce plugin up to 1.7.2

The WordPress plugin Pay With MetaMask For WooCommerce (Cryptocurrency Payment Gateway) up to 1.7.2 has an unauthenticated bypass vulnerability (CWE-345, CVSS 5.3). Update to 1.7.3 or later.

Vuln-watch · relayed from the NVD / CVE program; see Source & attribution below

Summary

Patchstack disclosed an unauthenticated bypass vulnerability (CVE-2026-107420, CWE-345 insufficient verification of data authenticity) in the WordPress plugin "Pay With MetaMask For WooCommerce - Cryptocurrency Payment Gateway". Patchstack describes it as allowing attackers to get around the plugin's security checks. CVSS 3.1 base score 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

Affected

  • cryptocurrency-payments-using-metamask-for-woocommerce (WordPress plugin) <= 1.7.2
  • Fixed in 1.7.3

Impact

An unauthenticated remote attacker can bypass a security check in the plugin, with low integrity impact per the CVSS vector. Patchstack rates the issue low priority and "unlikely to be exploited"; no exploitation in the wild is reported.

Recommended actions

  • Update the plugin to version 1.7.3 or later
  • Merchants using the plugin should reconcile recent crypto-paid orders against on-chain transactions

Source & attribution

This 0xCERT advisory summarises a disclosure by Patchstack (researcher credited: luffy): https://patchstack.com/database/wordpress/plugin/cryptocurrency-payments-using-metamask-for-woocommerce/vulnerability/wordpress-pay-with-metamask-for-woocommerce-cryptocurrency-payment-gateway-plugin-1-7-2-bypass-vulnerability-vulnerability and NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-107420. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-10-10 · last updated 2026-10-10

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0233/signed.txt | gpg --verify