plugin

Payu India Vulnerabilities

5 known security issues reported for the Payu India WordPress plugin. Most recent disclosed Jul 22, 2026.

2 critical 3 medium

Running Payu India on your site? Check whether your installed version is affected.

Scan your site free

PayU CommercePro Plugin <= 3.8.9 - Missing Authorization

medium

The PayU CommercePro Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.8.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.8.9
Fixed in:
3.9.0
Disclosed:
Jul 22, 2026

CVE-2026-61954 on NVD →

PayU CommercePro < 3.9.0 - Missing Authorization

medium

The PayU CommercePro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and excluding, 3.9.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.9.0
Fixed in:
3.9.0
Disclosed:
Jul 7, 2026

CVE-2026-13692 on NVD →

PayU CommercePro Plugin <= 3.8.7 - Authentication Bypass

critical

The PayU CommercePro Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.8.7. This is due to the plugin not properly verifying a user's identity through the update_cart_data() function. This makes it possible for unauthenticated attackers to log in as an administra...

CVSS:
9.8
Affected:
up to 3.8.7
Fixed in:
3.8.8
Disclosed:
Jun 5, 2025

CVE-2025-31022 on NVD →

PayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege Escalation

critical

The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to setting the users ID and au...

CVSS:
9.8
Affected:
up to 3.8.3
Fixed in:
3.8.4
Disclosed:
Jan 6, 2025

CVE-2024-12264 on NVD →

PayU India <= 3.8.8 - Reflected Cross-Site Scripting via type

medium

The PayU India plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘type’ parameter in versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...

CVSS:
6.1
Affected:
up to 3.8.8
Fixed in:
3.8.9
Disclosed:
Feb 26, 2024

CVE-2024-27193 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database