Security Alert Summary
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests. If the shared secret is left at its default empty value, unauthenticated attackers can forge payment confirmations and change the status of arbitrary orders.
CVE Details
- CVE ID:
CVE-2026-94299 - Affected component: elegro Crypto Payment WordPress plugin
- Affected versions: through 1.0.1 (<= 1.0.1)
- Published: October 6, 2026 at 7:17 AM UTC
- Last modified: October 6, 2026 at 3:18 PM UTC
- CVSS v3.1: Base score 6.5, Severity MEDIUM
Vector:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - Authentication / Privileges / User interaction: Privileges Required: NONE; User Interaction: NONE; Authentication required: none
- Primary impact: Confidentiality: LOW; Integrity: LOW; Availability: NONE
- CWE: CWE-863
Technical Details
The vulnerability exists because the plugin does not require a configured shared secret before accepting and trusting incoming payment notification requests. When the shared secret is left at its default empty value, incoming notifications are accepted without a valid authentication check. An unauthenticated attacker can craft and send forged payment notifications that the plugin will accept as legitimate, resulting in changed order statuses.
The report does not name specific function names or REST endpoints. The core issue is a missing verification step for incoming payment confirmations tied to the shared secret configuration.
Impact is limited to the integrity of order status data: attackers can mark orders as paid or otherwise modify order state, but the report does not describe direct privilege escalation, arbitrary code execution, or availability impacts.
How This Could Impact Your Website
Consider a small online store with a site owner, an internal store manager, and an external contractor who handles integrations. If the plugin on that site is using the default empty shared secret, an attacker could send forged payment notifications that change order statuses to “paid.” This can lead to incorrect fulfillment decisions, shipping goods without payment, financial reconciliation errors, and customer confusion.
If your site automatically sends email notifications when an order status changes, attackers could trigger those notifications. That may increase the risk of exposing customer email addresses in communications or enable targeted phishing that uses order-related context to appear legitimate.
If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Verify that a non-empty shared secret or equivalent notification authentication is configured for payment integrations.
- Review and reduce unnecessary user roles, especially contributor-level accounts.
- Enforce strong passwords and two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins.
- Monitor site activity and order logs for unusual behavior, such as unexpected status changes or payment confirmations without corresponding gateway records.
If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.