plugin

Payflex Payment Gateway Vulnerabilities

2 known security issues reported for the Payflex Payment Gateway WordPress plugin. Most recent disclosed Sep 30, 2024.

2 medium

Running Payflex Payment Gateway on your site? Check whether your installed version is affected.

Scan your site free

Payflex Payment Gateway <= 2.6.1 - Open Redirect

medium

The Payflex Payment Gateway plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.6.1. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully t...

CVSS:
6.1
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Sep 30, 2024

CVE-2024-47646 on NVD →

Payflex Payment Gateway <= 2.5.0 - Missing Authorization to Order Status Update

medium

The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to update the status of orders, which can potentially...

CVSS:
5.3
Affected:
up to 2.5.0
Fixed in:
2.6.0
Disclosed:
Jul 10, 2024

CVE-2024-0619 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database