Payplus
Payplus Payment Gateway: vulnerabilidades y CVE
Payplus Payment Gateway tiene 6 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-93620 | Media (6.5) | 0.19% | — | 23 sept 2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. |
| CVE-2026-12973 | Media (6.5) | 0.27% | — | 20 jul 2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret… |
| CVE-2026-12972 | Media (5.3) | 0.29% | — | 20 jul 2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the… |
| CVE-2024-37459 | Media (6.1) | 0.33% | — | 21 jul 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PayPlus LTD PayPlus Payment Gateway allows Reflected XSS.This issue affects PayPlus Payment Gateway: from n/a… |
| CVE-2024-6205 | Crítica (9.8) | 4.1% | — | 19 jul 2024 | The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to… |
| CVE-2024-37564 | Alta (8.5) | 0.40% | — | 12 jul 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7. |