Vulnerabilities and security researches forpayflex-payment-gateway payflex-payment-gateway
Direction: descendingOct 08, 2026
Payflex Payment Gateway # CVE-2026-103346
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 06, 2026
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
- Affected versions
-
max 2.7.1.
- Status
-
vulnerable
Oct 03, 2024
Payflex Payment Gateway # CVE-2024-47646
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 05, 2024
- Research Description
- URL Redirection to Untrusted Site ('Open Redirect') vulnerability in tomlister Payflex Payment Gateway payflex-payment-gateway.This issue affects Payflex Payment Gateway: from n/a through <= 2.6.1.
- Affected versions
-
max 2.6.2.
- Status
-
vulnerable
Jul 12, 2024
Payflex Payment Gateway # CVE-2024-0619
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 11, 2024
- Research Description
- The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to update the status of orders, which can potentially lead to revenue loss.
- Affected versions
-
max 2.6.0.
- Status
-
vulnerable