CRITICAL
9.1 CVE-2026-16947 Published 29 Aug 2026
WooCommerce Total Processing Plugin Path Traversal & Credential Disclosure
Worried this affects your website?
The Total processing card payments for WooCommerce WordPress plugin through 7.3 is affected.
Vulnerability: Unvalidated user-supplied path and lack of response authenticity verification.
Impact: Allows unauthenticated attackers to redirect payment gateway requests and forge success responses, potentially disclosing merchant's payment-gateway credentials and marking arbitrary orders as paid.
Reference: CVE-2026-16947 on NVD
← Back to Security News