plugin

Oceanpayment Creditcard Gateway Vulnerabilities

1 known security issue reported for the Oceanpayment Creditcard Gateway WordPress plugin. Most recent disclosed Oct 14, 2025.

1 medium

Running Oceanpayment Creditcard Gateway on your site? Check whether your installed version is affected.

Scan your site free

Oceanpayment CreditCard Gateway <= 6.0 - Missing Authentication to Unauthenticated Order Status Update

medium

The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification of data due to missing authentication and capability checks on the 'return_payment' and 'notice_payment' functions in all versions up to, and including, 6.0. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 6.0
Fix:
No patched version reported
Disclosed:
Oct 14, 2025

CVE-2025-11728 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database