CVE-2026-34891: IDPay WooCommerce Unauthenticated Data Exposure – HIGH Severity
The IDPay Payment Gateway plugin for WooCommerce versions 2.2.5 and earlier contains a flaw that allows attackers to access sensitive payment and transaction data without requiring any authentication. This means an unauthenticated attacker can retrieve confidential information directly over the network—no login credentials or special access needed. The vulnerability is classified as HIGH severity because it exposes sensitive data, though it does not allow attackers to modify data or disrupt service.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-497
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-34891 is an unauthenticated sensitive data exposure vulnerability (CWE-497: Exposure of Sensitive Information to an Unauthorized Actor) affecting IDPay Payment Gateway for WooCommerce up to version 2.2.5. The vulnerability has a CVSS 3.1 score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating network-accessible attack surface, no authentication or user interaction required, and confidentiality impact as the primary concern. The flaw permits unauthorized retrieval of sensitive payment transaction data through unauthenticated network requests.
Business impact
Organizations running affected versions of the IDPay WooCommerce plugin face direct exposure of customer payment data, transaction histories, and potentially personally identifiable information. This creates regulatory compliance violations under PCI DSS, GDPR, and similar data protection frameworks, with corresponding financial penalties, mandatory breach notifications, and reputational damage. Customer trust erosion and potential legal liability from inadequate data protection controls compound the business risk.
Affected systems
The vulnerability affects IDPay Payment Gateway for WooCommerce in versions 2.2.5 and earlier. This plugin is used by WooCommerce merchants to process payments through the IDPay gateway. Any WordPress site running WooCommerce with the affected IDPay plugin version is at risk. Organizations should audit their WooCommerce installations to identify current plugin versions and deployment scope.
Exploitability
This vulnerability requires only network access and no authentication, making it highly exploitable. An attacker can access sensitive data without logging in, solving puzzles, or user interaction. The straightforward attack surface—combined with the likelihood that many small-to-medium e-commerce operators may not promptly patch—suggests exploitation risk is moderate to high in the wild. However, the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed active exploitation has been publicly documented as of the publication date.
Remediation
Immediately upgrade the IDPay Payment Gateway for WooCommerce plugin to a version later than 2.2.5. Verify against the vendor's official advisory to confirm the exact patched version. After patching, review access logs for indicators of unauthorized data access prior to remediation. Consider implementing Web Application Firewall (WAF) rules to restrict suspicious data exfiltration patterns while patches are being deployed. Conduct a post-incident review to ensure payment data was not compromised.
Patch guidance
Apply the latest version of IDPay Payment Gateway for WooCommerce available from the official plugin repository or vendor. Verify the patched version number against the official IDPay or WooCommerce plugin advisory to ensure the security issue is addressed. Test the patched version in a staging environment before production deployment to confirm compatibility with your WooCommerce configuration. Schedule the update during a maintenance window to minimize customer impact. After upgrade, confirm the plugin version change in your WooCommerce administration panel.
Detection guidance
Monitor WooCommerce plugin version inventories to identify any installations running version 2.2.5 or earlier. Search web server logs and WordPress database logs for unauthorized API calls or data access requests to the IDPay payment gateway endpoint—particularly requests that retrieve transaction or payment data without valid authentication tokens. Implement application-level logging to track data access patterns. Use vulnerability scanning tools to detect the vulnerable plugin version across your infrastructure. Review access logs for anomalous patterns originating from external IP addresses targeting payment processing endpoints.
Why prioritize this
This vulnerability merits immediate priority because it enables unauthenticated access to sensitive payment data with no attack complexity, directly violating data protection regulations and creating customer liability exposure. While not yet in the CISA KEV catalog, the low barrier to exploitation and high-value target (payment information) make it an attractive target for opportunistic attackers. Organizations handling PCI-regulated data must treat this as urgent.
Risk score, explained
The CVSS 3.1 score of 7.5 (HIGH) reflects the combination of: (1) network-accessible attack vector requiring no authentication or user interaction, (2) high confidentiality impact (sensitive payment and transaction data exposure), and (3) no integrity or availability impact. The score appropriately captures the serious but non-critical nature of this data exfiltration flaw. Organizations processing payment data should treat this as a P1 issue regardless of CVSS score due to regulatory and customer trust implications.
Frequently asked questions
What data is exposed by this vulnerability?
The exact data exposed depends on the IDPay plugin configuration and what information is stored or transmitted through the gateway. Typically, this could include transaction IDs, order amounts, customer payment method details, and potentially PII linked to orders. Review your plugin logs and access patterns to determine what sensitive information may have been accessed. Consult the vendor advisory for specifics on the exposed endpoint.
How quickly should we patch this?
Given the HIGH severity, unauthenticated attack vector, and direct access to payment data, patching should be treated as an emergency. Most organizations should prioritize this within 24-48 hours of validating the patch availability and staging environment testing. If you process payment data subject to PCI DSS compliance, this may require even faster action to maintain compliance posture.
Is this vulnerability currently being exploited in the wild?
As of publication, this vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed public exploitation has been widely documented. However, the ease of exploitation and value of payment data mean active exploitation could occur once details become more widely known. Do not rely on the absence of KEV listing as a reason to delay patching.
How do we know if we were compromised before patching?
Review web server access logs for unauthorized requests to the IDPay payment gateway endpoints, particularly GET or POST requests that return transaction or payment data without valid authentication headers. Check for suspicious external IP addresses accessing these endpoints. If available, enable enhanced logging in WooCommerce and IDPay plugin settings to track data access events. Consider engaging forensics support to review payment data integrity and check for unauthorized exfiltration patterns.
This analysis is provided for informational purposes only and does not constitute legal, compliance, or professional security advice. Organizations should verify all technical details, patch availability, and compatibility requirements against official vendor advisories before taking remediation action. SEC.co makes no warranty regarding the accuracy or completeness of this intelligence and assumes no liability for consequences arising from its use. Always test security updates in staging environments before production deployment. For regulatory compliance obligations, consult legal and compliance teams regarding breach notification and data protection requirements specific to your jurisdiction and industry. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-0466MEDIUMAMD uProf Local Privilege Escalation and Denial of Service
- CVE-2026-24618MEDIUMHash Elements Information Disclosure – Patch Guidance
- CVE-2026-44743LOWSAP Business Objects Information Disclosure Vulnerability
- CVE-2026-49077MEDIUMWP eMember Information Disclosure Vulnerability
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk
- CVE-2016-20065HIGHUnauthenticated SQL Injection in Product Catalog 8 WordPress Plugin
- CVE-2016-20066HIGHWordPress CP Polls 1.0.8 Persistent XSS Vulnerability