plugin

Payhere Payment Gateway Vulnerabilities

4 known security issues reported for the Payhere Payment Gateway WordPress plugin. Most recent disclosed Jan 14, 2026.

2 medium

Running Payhere Payment Gateway on your site? Check whether your installed version is affected.

Scan your site free

PayHere Payment Gateway Plugin for WooCommerce [payhere-payment-gateway] <= 2.3.9 (unfixed)

unknown

[en] The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the statu...

Affected:
up to 2.3.9
Fix:
No patched version reported
Disclosed:
Jan 14, 2026

CVE-2025-15475 on NVD →

PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated Order Status Modification

medium

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of...

CVSS:
5.3
Affected:
up to 2.3.9
Fixed in:
2.4.0
Disclosed:
Jan 13, 2026

CVE-2025-15475 on NVD →

PayHere Payment Gateway Plugin for WooCommerce [payhere-payment-gateway] < 2.2.12

unknown

[en] The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.

Affected:
up to 2.2.12
Fixed in:
2.2.12
Disclosed:
Jan 1, 2024

CVE-2023-6064 on NVD →

PayHere Payment Gateway <= 2.2.11 - Information Disclosure via Log Files

medium

The PayHere Payment Gateway plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.11 via the payhere_log() function. This makes it possible for unauthenticated attackers to extract sensitive data from the log files generated by the plugin.

CVSS:
5.3
Affected:
up to 2.2.11
Fixed in:
2.2.12
Disclosed:
Dec 7, 2023

CVE-2023-6064 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database