EIP-2026-109242
PRE-CVEMagento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109242. PoCs published by GeekHack.
AI-analyzed exploit summary This exploit demonstrates a lack of origin authentication in the CardGate Payment Gateway for Magento, allowing an attacker to replace critical plugin settings (merchant ID, secret key) via a crafted IPN callback request. It can spoof order statuses or redirect payments to an attacker-controlled account.
Description
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
Exploits (1)
This exploit demonstrates a lack of origin authentication in the CardGate Payment Gateway for Magento, allowing an attacker to replace critical plugin settings (merchant ID, secret key) via a crafted IPN callback request. It can spoof order statuses or redirect payments to an attacker-controlled account.