CVE-2026-0692 Details
Description
The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determine the client IP address. This makes it possible for unauthenticated attackers to bypass IP allowlist restrictions by spoofing a whitelisted BlueSnap IP address and send forged IPN (Instant Payment Notification) data to manipulate order statuses (mark orders as paid, failed, refunded, or on-hold) without proper authorization.
A vulnerability exists in the BlueSnap Payment Gateway for WooCommerce plugin for WordPress, affecting all versions up to and including 3.3.0. The issue arises from the plugin's reliance on WooCommerce's WC_Geolocation::get_ip_address() function to validate Instant Payment Notification (IPN) requests. This method trusts user-controlled headers, such as X-Real-IP and X-Forwarded-For, to determine the client's IP address. As a result, unauthenticated attackers can spoof a whitelisted BlueSnap IP address to bypass IP allowlist restrictions and send forged IPN data. This manipulation can be used to arbitrarily change order statuses—marking orders as paid, failed, refunded, or on hold—without proper authorization.
No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 14, 2026CISA-ADP
Assessed Feb 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BlueSnap Payment Gateway | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | CVE Modified | [email protected] |
| Feb 14, 2026 | New CVE Received | [email protected] |
Volerion