Payflex Payment Gateway <= 2.6.1 - Open Redirect
medium
The Payflex Payment Gateway plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.6.1. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Sep 30, 2024
CVE-2024-47646 on NVD →
Payflex Payment Gateway <= 2.5.0 - Missing Authorization to Order Status Update
medium
The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to update the status of orders, which can potentially...
- CVSS:
- 5.3
- Affected:
- up to 2.5.0
- Fixed in:
- 2.6.0
- Disclosed:
- Jul 10, 2024
CVE-2024-0619 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database