
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0679 is an authorization bypass vulnerability in the Fortis for WooCommerce WordPress plugin affecting all versions up to and including 1.2.0. The flaw stems from an inverted nonce check in the check_fortis_notify_response function, allowing unauthenticated attackers to arbitrarily update WooCommerce order statuses to paid, processing, or completed — effectively enabling fraudulent order fulfillment without actual payment. It was published on February 4, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization). The check_fortis_notify_response function, which handles payment gateway callback notifications, performs a nonce validation check with inverted logic — effectively treating invalid nonces as valid and vice versa. This means any unauthenticated HTTP request can bypass the intended authorization gate and trigger order status updates. The vulnerable code is visible in the plugin's source at line 1674 of WC_Gateway_Fortis.php (WordPress Trac, Wordfence).
Successful exploitation allows unauthenticated attackers to mark arbitrary WooCommerce orders as paid or completed without completing any actual payment transaction, resulting in direct financial loss for store operators. The integrity impact is limited to order status manipulation — there is no confidentiality or availability impact. Attackers could exploit this to fraudulently obtain goods or services from affected online stores at no cost (Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of writing. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.059%, indicating a low probability of near-term exploitation (Feedly, Wordfence). However, the low attack complexity and lack of authentication requirements make it an attractive target for opportunistic attackers targeting e-commerce sites.
readme.txt files.check_fortis_notify_response.paid, processing, or completed). Due to the inverted nonce check, any nonce value (or none at all) will pass validation.paid, processing, or completed status without corresponding payment records in the Fortis payment gateway dashboard; orders with no associated payment transaction ID showing as completed.Store administrators should update the Fortis for WooCommerce plugin to a version beyond 1.2.0 that contains a corrected nonce validation implementation. If an updated version is not yet available, consider temporarily deactivating the plugin and using an alternative payment gateway until a patch is released. Additionally, monitor WooCommerce order logs for anomalous status changes and restrict access to payment callback endpoints via web application firewall (WAF) rules where possible (Wordfence).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of February 2–8, 2026, and published details in their threat intelligence database (Wordfence Blog). The vulnerability was also picked up by security aggregators including Infinit Security and national CERTs such as INCIBE-CERT (Spain) and CCN-CERT. No significant social media discussion or notable researcher commentary beyond standard aggregation has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."