Security Brief: CVE-2026-16947 WooCommerce Payment Plugin Flaw Enables Payment Bypass and Credential Theft
CVE-2026-16947 is a critical unauthenticated vulnerability in the Total Processing Card Payments for WooCommerce plugin through version 7.3. Attackers can abuse server-side request forgery to redirect payment verification requests, expose payment-gateway credentials, and potentially mark arbitrary WooCommerce orders as paid.