CVE-2026-0679: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0679 is an authorization bypass vulnerability in the Fortis for WooCommerce WordPress plugin affecting all versions up to and including 1.2.0. The flaw stems from an inverted nonce check in the check_fortis_notify_response function, allowing unauthenticated attackers to arbitrarily update WooCommerce order statuses to paid, processing, or completed — effectively enabling fraudulent order fulfillment without actual payment. It was published on February 4, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). The check_fortis_notify_response function, which handles payment gateway callback notifications, performs a nonce validation check with inverted logic — effectively treating invalid nonces as valid and vice versa. This means any unauthenticated HTTP request can bypass the intended authorization gate and trigger order status updates. The vulnerable code is visible in the plugin's source at line 1674 of WC_Gateway_Fortis.php (WordPress Trac, Wordfence).

Impact

Successful exploitation allows unauthenticated attackers to mark arbitrary WooCommerce orders as paid or completed without completing any actual payment transaction, resulting in direct financial loss for store operators. The integrity impact is limited to order status manipulation — there is no confidentiality or availability impact. Attackers could exploit this to fraudulently obtain goods or services from affected online stores at no cost (Wordfence).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of writing. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.059%, indicating a low probability of near-term exploitation (Feedly, Wordfence). However, the low attack complexity and lack of authentication requirements make it an attractive target for opportunistic attackers targeting e-commerce sites.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Fortis for WooCommerce plugin (version ≤ 1.2.0) via passive scanning tools (e.g., WPScan, Shodan) or by checking plugin metadata in publicly accessible readme.txt files.
  2. Identify the callback endpoint: Locate the payment notification callback URL registered by the plugin, typically a WooCommerce webhook or IPN endpoint that invokes check_fortis_notify_response.
  3. Craft a malicious request: Send an unauthenticated HTTP POST request to the callback endpoint with parameters specifying a target order ID and a desired status (e.g., paid, processing, or completed). Due to the inverted nonce check, any nonce value (or none at all) will pass validation.
  4. Trigger order status update: The function processes the request and updates the specified WooCommerce order status to the attacker-chosen value, marking it as paid without any actual payment being processed.
  5. Obtain goods/services: The attacker can then claim fulfillment of the fraudulently marked order (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected or repeated unauthenticated POST requests to the Fortis WooCommerce payment callback/IPN endpoint from unknown IP addresses.
  • Logs: WordPress/WooCommerce access logs showing POST requests to the payment notification handler with unusual or missing nonce values; order status change events in WooCommerce logs not correlated with legitimate payment gateway activity.
  • Application: WooCommerce orders unexpectedly transitioning to paid, processing, or completed status without corresponding payment records in the Fortis payment gateway dashboard; orders with no associated payment transaction ID showing as completed.

Mitigation and workarounds

Store administrators should update the Fortis for WooCommerce plugin to a version beyond 1.2.0 that contains a corrected nonce validation implementation. If an updated version is not yet available, consider temporarily deactivating the plugin and using an alternative payment gateway until a patch is released. Additionally, monitor WooCommerce order logs for anomalous status changes and restrict access to payment callback endpoints via web application firewall (WAF) rules where possible (Wordfence).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of February 2–8, 2026, and published details in their threat intelligence database (Wordfence Blog). The vulnerability was also picked up by security aggregators including Infinit Security and national CERTs such as INCIBE-CERT (Spain) and CCN-CERT. No significant social media discussion or notable researcher commentary beyond standard aggregation has been observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management