plugin

Ipospays Gateways Wc Vulnerabilities

1 known security issue reported for the Ipospays Gateways Wc WordPress plugin. Most recent disclosed Feb 7, 2026.

1 medium

Running Ipospays Gateways Wc on your site? Check whether your installed version is affected.

Scan your site free

iPOSpays Gateways WC <= 1.3.7 - Unauthenticated Missing Authorization to Settings Update via REST API Endpoint

medium

The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin exposing a REST API endpoint /wp-json/ipospays/v1/save_settings with 'permission_callback' set to '__return_true', which allows unauthenticated access without any capabil...

CVSS:
5.3
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Feb 7, 2026

CVE-2026-39608 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database