Vulnerabilities
Summary — last 7 days
New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
118 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | High (7.5) | — | — | Paytm Payment GatewayAI | 10/1/2026 | 10/1/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection… | |
| Received | High (7.5) | — | — | Paytm Payment GatewayAI | 10/1/2026 | 10/1/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts… | |
| Deferred | Medium (6.5) | 0.25% | — | Conekta Payment GatewayAI | 9/23/2026 | 9/23/2026 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. | |
| Deferred | Medium (6.5) | 0.19% | — | Payplus Payment GatewayAI | 9/23/2026 | 9/23/2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| Deferred | Medium (5.3) | 0.18% | — | Sumit Payment GatewayAI | 9/23/2026 | 9/24/2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment. | |
| Deferred | Medium (5.3) | 0.16% | — | Angelleye Payment Gateway FOR Paypal ON WoocommerceAI | 9/21/2026 | 9/22/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own… | |
| Deferred | Medium (5.3) | 0.38% | — | WT Stripe Payment Gateway Stripe FOR WoocommerceAI | 9/19/2026 | 9/21/2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only… | |
| Deferred | Low (3.7) | 0.14% | — | Robokassa Payment Gateway FOR WoocommerceAI | 9/17/2026 | 9/18/2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold… | |
| Deferred | Critical (10) | 0.50% | — | Cryptopayment GatewayAI | 9/13/2026 | 9/14/2026 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored… | |
| Deferred | Medium (5.9) | 0.16% | — | Payment Gateway PaypayAI | 9/11/2026 | 9/11/2026 | The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them. | |
| Deferred | Medium (6.5) | 0.33% | — | Robokassa Payment Gateway FOR WoocommerceAI | 9/10/2026 | 9/10/2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |
| Deferred | Medium (5.3) | 0.16% | — | Epayco Payment GatewayAI | 9/4/2026 | 9/8/2026 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | |
| Deferred | Medium (5.3) | 0.33% | — | Conekta Payment GatewayAI | 8/22/2026 | 8/26/2026 | The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. | |
| Deferred | Medium (6.5) | 0.42% | — | Piraeus Bank Woocommerce Payment GatewayAI | 8/18/2026 | 8/20/2026 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | |
| Deferred | High (7.5) | 0.42% | — | Duitku Payment GatewayAI | 8/18/2026 | 8/20/2026 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | |
| Deferred | High (7.5) | 0.35% | — | Clink Bitcoin Lightning Payment GatewayAI | 8/13/2026 | 8/14/2026 | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| Deferred | Medium (5.3) | 0.16% | — | Paypal Payment Gateway FOR WoocommerceAI | 8/12/2026 | 8/26/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the… | |
| Deferred | High (7.5) | 0.19% | — | Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI | 8/6/2026 | 8/26/2026 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own… | |
| Deferred | High (7.5) | 0.36% | — | Clover Payment Gateway BY ZaytechAI | 7/27/2026 | 7/27/2026 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by… | |
| Deferred | High (7.5) | 0.35% | — | Payment Gateway FOR PaypalAI | 7/23/2026 | 7/23/2026 | Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | |
| Deferred | Medium (6.5) | 0.27% | — | Payplus Payment GatewayAI | 7/20/2026 | 7/21/2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses. | |
| Deferred | Medium (5.3) | 0.29% | — | Payplus Payment GatewayAI | 7/20/2026 | 7/21/2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. | |
| Deferred | High (7.2) | 0.56% | — | Corvuspay Woocommerce Payment GatewayAI | 7/11/2026 | 7/13/2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Deferred | Medium (5.3) | 0.47% | — | Corvuspay Woocommerce Payment GatewayAI | 7/9/2026 | 7/9/2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any… | |
| Deferred | Critical (9.8) | 0.56% | — | Novalnet Payment GatewayAI | 7/2/2026 | 7/2/2026 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. |