plugin

Trust Payments Gateway 3Ds2 Vulnerabilities

6 known security issues reported for the Trust Payments Gateway 3Ds2 WordPress plugin. Most recent disclosed Jul 4, 2025.

2 high 1 medium

Running Trust Payments Gateway 3Ds2 on your site? Check whether your installed version is affected.

Scan your site free

Trust Payments Gateway for WooCommerce (JavaScript Library) [trust-payments-gateway-3ds2] < 1.3.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Library) allows Cross Site Request Forgery. This issue affects Trust Payments Gateway for WooCommerce (JavaScript Library): from n/a through 1.3.6.

Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Jul 4, 2025

CVE-2025-53569 on NVD →

Trust Payments Gateway for WooCommerce (JavaScript Library) <= 1.3.6 - Cross-Site Request Forgery

medium

The Trust Payments Gateway for WooCommerce (JavaScript Library) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorize...

CVSS:
4.3
Affected:
up to 1.3.6
Fixed in:
1.3.7
Disclosed:
Jul 3, 2025

CVE-2025-53569 on NVD →

Trust Payments Gateway (3DS2) <= 1.2.0 - Cross-Site Request Forgery

high

The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing nonce validation on the tpgw_refund_purchase() function. This makes it possible for unauthenticated attackers to refund order purchases via a forged request...

CVSS:
8.8
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Jul 26, 2022

Trust Payments Gateway (3DS2) <= 1.2.2 - Cross-Site Request Forgery

high

The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing nonce validation on several functions like tpgw_create_new_user() and tpgw_update_address_myst(). This makes it possible for unauthenticated attackers to per...

CVSS:
8.8
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Jul 26, 2022

Trust Payments Gateway for WooCommerce (JavaScript Library) [trust-payments-gateway-3ds2] < 1.2.1

unknown

The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing nonce validation on the tpgw_refund_purchase() function. This makes it possible for unauthenticated attackers to refund order purchases via a forged request...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Jul 26, 2022

Trust Payments Gateway for WooCommerce (JavaScript Library) [trust-payments-gateway-3ds2] < 1.2.3

unknown

The Trust Payments Gateway (3DS2) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing nonce validation on several functions like tpgw_create_new_user() and tpgw_update_address_myst(). This makes it possible for unauthenticated attackers to per...

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Jul 26, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database