cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forepayco-gateway epayco-gateway

Direction: ascending
Aug 29, 2026

ePayco plugin for WooCommerce # CVE-2026-78260

CVE, Research URL

CVE-2026-78260

Date
Aug 27, 2026
Research Description
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Affected versions
max 8.4.7.
Status
vulnerable
Sep 06, 2026

ePayco plugin for WooCommerce # CVE-2026-84043

CVE, Research URL

CVE-2026-84043

Date
Sep 04, 2026
Research Description
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
Affected versions
max 8.4.7.
Status
vulnerable