Summary
CVE-2026-15205 is an unauthenticated SQL injection vulnerability in the Paymob for WooCommerce WordPress plugin, affecting all versions before 4.1.9. The flaw resides in the plugin’s public payment callback endpoint, where a client-supplied identifier used for a "pixel lookup" is passed into a SQL query without sanitization before the payment provider’s HMAC signature is verified. The issue carries a High severity CVSS score of 8.6, as it allows remote, unauthenticated attackers to extract arbitrary data from the WordPress database.
Technical details
- Root cause: The plugin’s Paymob callback handler builds a SQL query using a client-supplied identifier (used to look up a stored payment "pixel") without proper input sanitization.
- Trigger condition: The vulnerable query executes before the plugin validates the HMAC signature that is meant to authenticate legitimate callback requests from Paymob, meaning no valid signature or prior authentication is required to reach the injectable code.
- Attack vector: The callback endpoint is public-facing and unauthenticated, reachable over the network (AV:N) with low attack complexity and no user interaction.
- Impact: Attackers can perform both in-band (reflected) and time-based blind SQL injection to read arbitrary data from the database, including user credentials and other secrets. The vulnerability affects confidentiality only (no integrity or availability impact), and the CVSS scope is "Changed."
Affected software
- Paymob for WooCommerce (WordPress plugin) — all versions prior to 4.1.9
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade Paymob for WooCommerce to version 4.1.9 or later, where the callback input is properly sanitized/validated before use in SQL queries.
- If unable to patch immediately: Restrict or monitor access to the plugin’s payment callback endpoint at the network/WAF layer for anomalous query-string patterns and time-based request timing typical of blind SQLi, and audit database access logs for suspicious activity until the update can be applied.

