Vulnerabilities and security researches forepayco-gateway epayco-gateway
Direction: ascendingAug 29, 2026
ePayco plugin for WooCommerce # CVE-2026-78260
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 27, 2026
- Research Description
- Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
- Affected versions
-
max 8.4.7.
- Status
-
vulnerable
Sep 06, 2026
ePayco plugin for WooCommerce # CVE-2026-84043
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 04, 2026
- Research Description
- The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
- Affected versions
-
max 8.4.7.
- Status
-
vulnerable