HomeCVE Intelligence › CVE-2026-11575
CVSS 9.1 CRITICAL Vulnerability

CVE-2026-11575: CVE-2026-11575 - PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via F…

CVE ID : CVE-2026-11575 Published : July 17, 2026, 6 a.m. | 59minutes ago Description : The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks…

9.1CVSS Score
CRITICALSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-11575
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeVulnerability
CVSS Score9.1 (CRITICAL)
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

CVE ID : CVE-2026-11575

Published : July 17, 2026, 6 a.m. | 59minutes ago

Description : The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body that anyone can compute. This allows unauthenticated attackers to forge a paym

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-11575","confidence_score":23.5,"first_seen":"2026-07-17","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-11575 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence