CVE-2026-92430: Unknown Rede Itaú For Woocommerce — Payment Pix, Credit Card And Debit

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.

Affected products

  • Unknown Rede Itaú For Woocommerce — Payment Pix, Credit Card And Debit: from 3.6.1, before 5.4.7 (fixed in 5.4.7)

Published 2026-09-19. Last modified 2026-09-21.