cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpayplus-payment-gateway payplus-payment-gateway

Direction: ascending
Jul 03, 2024

PayPlus Payment Gateway # CVE-2024-6205

CVE, Research URL

CVE-2024-6205

Date
Jul 19, 2024
Research Description
The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.
Affected versions
max 6.6.9.
Status
vulnerable
Jul 05, 2024

PayPlus Payment Gateway # CVE-2024-37459

CVE, Research URL

CVE-2024-37459

Date
Jul 22, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PayPlus LTD PayPlus Payment Gateway allows Reflected XSS.This issue affects PayPlus Payment Gateway: from n/a through 6.6.8.
Affected versions
max 6.6.9.
Status
vulnerable
Jul 12, 2024

PayPlus Payment Gateway # CVE-2024-37564

CVE, Research URL

CVE-2024-37564

Date
Jul 12, 2024
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7.
Affected versions
max 7.0.8.
Status
vulnerable
Jul 23, 2026

PayPlus Payment Gateway # CVE-2026-12973

CVE, Research URL

CVE-2026-12973

Date
Jul 20, 2026
Research Description
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
Affected versions
max 8.2.2.
Status
vulnerable

PayPlus Payment Gateway # CVE-2026-12972

CVE, Research URL

CVE-2026-12972

Date
Jul 20, 2026
Research Description
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
Affected versions
max 8.2.2.
Status
vulnerable