-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0233 ============================================================ Advisory-ID: 0xCERT-2026-0233 Severity: Medium Published: 2026-10-10T20:16:32.000Z Updated: 2026-10-10T20:35:58.564Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0233 Title: Unauthenticated security-check bypass in Pay With MetaMask for WooCommerce plugin up to 1.7.2 Summary - ------- The WordPress plugin Pay With MetaMask For WooCommerce (Cryptocurrency Payment Gateway) up to 1.7.2 has an unauthenticated bypass vulnerability (CWE-345, CVSS 5.3). Update to 1.7.3 or later. Details - ------- Summary Patchstack disclosed an unauthenticated bypass vulnerability (CVE-2026-107420, CWE-345 insufficient verification of data authenticity) in the WordPress plugin "Pay With MetaMask For WooCommerce - Cryptocurrency Payment Gateway". Patchstack describes it as allowing attackers to get around the plugin's security checks. CVSS 3.1 base score 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Affected - - cryptocurrency-payments-using-metamask-for-woocommerce (WordPress plugin) <= 1.7.2 - - Fixed in 1.7.3 Impact An unauthenticated remote attacker can bypass a security check in the plugin, with low integrity impact per the CVSS vector. Patchstack rates the issue low priority and "unlikely to be exploited"; no exploitation in the wild is reported. Recommended actions - - Update the plugin to version 1.7.3 or later - - Merchants using the plugin should reconcile recent crypto-paid orders against on-chain transactions Source & attribution This 0xCERT advisory summarises a disclosure by Patchstack (researcher credited: luffy): https://patchstack.com/database/wordpress/plugin/cryptocurrency-payments-using-metamask-for-woocommerce/vulnerability/wordpress-pay-with-metamask-for-woocommerce-cryptocurrency-payment-gateway-plugin-1-7-2-bypass-vulnerability-vulnerability and NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-107420. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://patchstack.com/database/wordpress/plugin/cryptocurrency-payments-using-metamask-for-woocommerce/vulnerability/wordpress-pay-with-metamask-for-woocommerce-cryptocurrency-payment-gateway-plugin-1-7-2-bypass-vulnerability-vulnerability - - CVE-2026-107420 - - https://nvd.nist.gov/vuln/detail/CVE-2026-107420 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrMIpoJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmdmfM3F63eZwDRya47hFq6ctGD7e0A/YljTnuJk tJQZihYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAADHFQEAiDzc5ZhZ2C20wi+X 9TStGEnLVfSuivzOzY00gbKfD2oBAKo5oz8W+XTKFVID1HvVqWKEsAUeYPrh 6sc9glab6+UJ =SUpY -----END PGP SIGNATURE-----