Description
The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and including, 2.8.4. This is due to a flawed permission check in the `paidy_webhook_permission_check` function that unconditionally returns `true` when the webhook signature header is omitted. This makes it possible for unauthenticated attackers to bypass payment verification and fraudulently mark orders as "Processing" or "Completed" without actual payment via a crafted POST request to the Paidy webhook endpoint.
INFO
Published Date :
2026-02-27T09:23:43.326Z
Last Modified :
2026-02-27T15:39:31.362Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2026-1305 vulnerability.
| Vendors | Products |
|---|---|
| Shoheitanaka |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-1305.