CVE-2026-0692P2HIGHCVSS 7.5PoC≤ 3.4.02026-02-14
CVE-2026-0692 [HIGH] CWE-862 CVE-2026-0692: The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authoriza
The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like X-Real-IP and X-Forwarded-For to determi
nvd