securityonline.info 6/17/2026, 7:21:01 AM · external

WooCommerce stores hit by payment skimmer (CVE-2026-48907)

WooCommerce stores hit by payment skimmer (CVE-2026-48907)
Developing story vulnerability 12 articles tracked
CISA adds Joomla Content Editor flaw (CVE-2026-48907) to KEV catalogue
CyberSIXT Evidence Panel
Primary Source cloudsek.com
CISA KEV Listed in KEV
Patch Patch Available

A critical alert highlights the discovery of a WooCommerce payment skimmer (CVE-2026-48907) that compromises online stores by stealing card details during legitimate transactions. Cybercriminals have shifted from phishing tactics to directly targeting e-commerce sites, injecting JavaScript skimmers into checkout pages. The skimmer mimics the Stripe payment form, capturing sensitive data such as card numbers and CVVs while remaining undetectable to the user.

It disguises its presence, storing data using common tracking keys and encoding stolen information to evade detection. This stealthy method makes it difficult to identify the theft, with dwell times often lasting months. Merchants are urged to implement security measures against this evolving threat.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline