CVE-2026-87981

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.

  • Published Sep 23, 2026
  • CVSS 4.7 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-87981 at the National Vulnerability Database