CRITICAL 9.1 CVE-2026-16947 Published 29 Aug 2026

WooCommerce Total Processing Plugin Path Traversal & Credential Disclosure

Worried this affects your website?

The Total processing card payments for WooCommerce WordPress plugin through 7.3 is affected.

Vulnerability: Unvalidated user-supplied path and lack of response authenticity verification.

Impact: Allows unauthenticated attackers to redirect payment gateway requests and forge success responses, potentially disclosing merchant's payment-gateway credentials and marking arbitrary orders as paid.

Reference: CVE-2026-16947 on NVD

← Back to Security News