Vulnerabilities

Summary — last 7 days

New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
–

118 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedHigh (7.5)——Paytm Payment GatewayAI10/1/202610/1/2026
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection…
ReceivedHigh (7.5)——Paytm Payment GatewayAI10/1/202610/1/2026
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts…
DeferredMedium (6.5)0.25%—Conekta Payment GatewayAI9/23/20269/23/2026
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
DeferredMedium (6.5)0.19%—Payplus Payment GatewayAI9/23/20269/23/2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
DeferredMedium (5.3)0.18%—Sumit Payment GatewayAI9/23/20269/24/2026
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
DeferredMedium (5.3)0.16%—Angelleye Payment Gateway FOR Paypal ON WoocommerceAI9/21/20269/22/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own…
DeferredMedium (5.3)0.38%—WT Stripe Payment Gateway Stripe FOR WoocommerceAI9/19/20269/21/2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only…
DeferredLow (3.7)0.14%—Robokassa Payment Gateway FOR WoocommerceAI9/17/20269/18/2026
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold…
DeferredCritical (10)0.50%—Cryptopayment GatewayAI9/13/20269/14/2026
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored…
DeferredMedium (5.9)0.16%—Payment Gateway PaypayAI9/11/20269/11/2026
The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.
DeferredMedium (6.5)0.33%—Robokassa Payment Gateway FOR WoocommerceAI9/10/20269/10/2026
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
DeferredMedium (5.3)0.16%—Epayco Payment GatewayAI9/4/20269/8/2026
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
DeferredMedium (5.3)0.33%—Conekta Payment GatewayAI8/22/20268/26/2026
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
DeferredMedium (6.5)0.42%—Piraeus Bank Woocommerce Payment GatewayAI8/18/20268/20/2026
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
DeferredHigh (7.5)0.42%—Duitku Payment GatewayAI8/18/20268/20/2026
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
DeferredHigh (7.5)0.35%—Clink Bitcoin Lightning Payment GatewayAI8/13/20268/14/2026
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
DeferredMedium (5.3)0.16%—Paypal Payment Gateway FOR WoocommerceAI8/12/20268/26/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the…
DeferredHigh (7.5)0.19%—Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI8/6/20268/26/2026
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own…
DeferredHigh (7.5)0.36%—Clover Payment Gateway BY ZaytechAI7/27/20267/27/2026
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by…
DeferredHigh (7.5)0.35%—Payment Gateway FOR PaypalAI7/23/20267/23/2026
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
DeferredMedium (6.5)0.27%—Payplus Payment GatewayAI7/20/20267/21/2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
DeferredMedium (5.3)0.29%—Payplus Payment GatewayAI7/20/20267/21/2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
DeferredHigh (7.2)0.56%—Corvuspay Woocommerce Payment GatewayAI7/11/20267/13/2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
DeferredMedium (5.3)0.47%—Corvuspay Woocommerce Payment GatewayAI7/9/20267/9/2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any…
DeferredCritical (9.8)0.56%—Novalnet Payment GatewayAI7/2/20267/2/2026
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.