PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink
medium
The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or incorrect nonce validation on the peachpay_stripe_handle_admin_actio...
- CVSS:
- 4.3
- Affected:
- up to 1.120.46
- Fixed in:
- 1.120.47
- Disclosed:
- May 27, 2026
CVE-2026-9618 on NVD →
PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) <= 1.119.8 - Missing Authorization to Unauthenticated Order Status Modification
medium
The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay webhook REST endpoint in all versions up to, and including, 1.119.8. This makes it pos...
- CVSS:
- 5.3
- Affected:
- up to 1.119.8
- Fixed in:
- 1.119.9
- Disclosed:
- Jan 19, 2026
CVE-2025-14978 on NVD →
Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.117.5 - Authenticated (Contributor+) SQL Injection via order_by Parameter
medium
The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 1.117.5 due to insufficient escaping on the user supplied parameter and lack of sufficient prep...
- CVSS:
- 6.5
- Affected:
- up to 1.117.5
- Fixed in:
- 1.117.6
- Disclosed:
- Sep 9, 2025
CVE-2025-9463 on NVD →
PeachPay Payments <= 1.117.4 - Missing Authorization
medium
The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.117.4. This makes it possible for unauthenticated attackers to perform an unaut...
- CVSS:
- 5.3
- Affected:
- up to 1.117.4
- Fixed in:
- 1.117.5
- Disclosed:
- Sep 3, 2025
CVE-2025-58634 on NVD →
Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.112.0 - Reflected Cross-Site Scripting
medium
The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.112.0. This makes it possible for unauthenti...
- CVSS:
- 6.1
- Affected:
- up to 1.112.0
- Fixed in:
- 1.113.0
- Disclosed:
- Nov 22, 2024
CVE-2024-11362 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database