EIP-2026-109242

PRE-CVE

Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109242. PoCs published by GeekHack.

AI-analyzed exploit summary This exploit demonstrates a lack of origin authentication in the CardGate Payment Gateway for Magento, allowing an attacker to replace critical plugin settings (merchant ID, secret key) via a crafted IPN callback request. It can spoof order statuses or redirect payments to an attacker-controlled account.

Description

Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass

Exploits (1)

exploitdb WORKING POC
by GeekHack · phpwebappsphp
https://www.exploit-db.com/exploits/48135

This exploit demonstrates a lack of origin authentication in the CardGate Payment Gateway for Magento, allowing an attacker to replace critical plugin settings (merchant ID, secret key) via a crafted IPN callback request. It can spoof order statuses or redirect payments to an attacker-controlled account.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Magento WooCommerce CardGate Payment Gateway <= 2.0.30
No auth needed
Prerequisites: Access to a public URL to host the script · A registered merchant account on CardGate · Target store URL and order details
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026