CVE-2026-0939

Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Unauthenticated Order Status Manipulation

The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verification of data authenticity in all versions up to, and including, 5.1.2. This is due to the plugin failing to verify the authenticity of payment callbacks. This makes it possible for unauthenticated attackers to manipulate WooCommerce order statuses, either marking unpaid orders as paid, or failed.


We have discovered 205 live websites that are affected by CVE-2026-0939.

Run a Free Instant Scan




Affected Software

Product  Woo Rede
Category Wordpress Plugins
Vulnerable Domains205 live websites (100% of Woo Rede install base)
Vulnerable Versions
  • from 0 through 5.1.2
Vulnerable Versions Count21 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-345 Insufficient Verification of Data Authenticity



Details

  • Published - Jan 16, 2026
  • Updated - Jan 16, 2026

Credits

  • Osvaldo Noe Gonzalez Del Rio (finder)

Website Distribution by Country

Number of websites using CVE-2026-0939
United States19 websites



Brazil182 websites
Germany2 websites
Cyprus1 websites
Singapore1 websites

Website Distribution by TLD

Number of websites using CVE-2026-0939
.com.br179 websites
.com13 websites
.net1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-0939

Top websites that are affected by CVE-2026-0939. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.***.br Brazil***,***
****.***.br United States***,***
*********.***.br Brazil***,***
****.***.br Brazil*,***,***
********.***.br United States*,***,***
****.***.br Brazil*,***,***
***.***.br Brazil*,***,***
******************.***.br Brazil*,***,***
******.***.br Brazil*,***,***
********.***.br Brazil*,***,***
See full domain list

FAQ

CVE-2026-0939 is Insufficient Verification of Data Authenticity in Woo Rede
A total of 205 websites have been identified as vulnerable to CVE-2026-0939, based on global website indexing conducted by WebTechSurvey.
The Woo Rede is affected by the CVE-2026-0939 vulnerability.
Woo Rede versions up to and including 5.1.2 are vulnerable to CVE-2026-0939.