plugin

Woocommerce Mercadopago Vulnerabilities

9 known security issues reported for the Woocommerce Mercadopago WordPress plugin. Most recent disclosed Aug 5, 2026.

5 medium

Running Woocommerce Mercadopago on your site? Check whether your installed version is affected.

Scan your site free

Mercado Pago payments for WooCommerce <= 8.9.0 - Unauthenticated Insecure Direct Object Reference

medium

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 8.9.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 8.9.0
Fixed in:
8.9.1
Disclosed:
Aug 5, 2026

CVE-2026-28180 on NVD →

Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticated PIX Payment QR Code Image Disclosure

medium

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code...

CVSS:
5.3
Affected:
up to 8.7.11
Fixed in:
8.7.12
Disclosed:
May 5, 2026

CVE-2026-3208 on NVD →

Mercado Pago payments for WooCommerce [woocommerce-mercadopago] < 7.6.2

unknown

[en] The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download and read the contents of arbitrary files on the...

Affected:
up to 7.6.2
Fixed in:
7.6.2
Disclosed:
Jul 20, 2024

CVE-2024-3934 on NVD →

Mercado Pago payments for WooCommerce 7.3.0 - 7.6.1 - Authenticated (Subscriber+) Arbitrary File Download

medium

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes it possible for authenticated attackers, with subscriber-level access and above, to download and read the contents of arbitrary files on the serve...

CVSS:
6.5
Affected:
7.3.0 – 7.6.1
Fixed in:
7.6.2
Disclosed:
Jul 19, 2024

CVE-2024-3934 on NVD →

Mercado Pago payments for WooCommerce [woocommerce-mercadopago] < 6.4.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1.

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Mar 1, 2023

CVE-2022-45068 on NVD →

Mercado Pago payments for WooCommerce <= 6.3.1 - Cross-Site Request Forgery

medium

The Mercado Pago payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0. This is due to missing or incorrect nonce validation on the multiple functions. This makes it possible for unauthenticated attackers to trick other users or visitors into creating or pro...

CVSS:
4.3
Affected:
up to 6.3.1
Fixed in:
6.4.0
Disclosed:
Feb 6, 2023

CVE-2022-45068 on NVD →

Mercado Pago payments for WooCommerce [woocommerce-mercadopago] < 6.7.0

unknown

Update the WordPress Mercado Pago payments for WooCommerce plugin to the latest available version (at least 6.7.0). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Mercado Pago payments for WooCommerce Plugin. This could allow a malicious actor to force higher privilege...

Affected:
up to 6.7.0
Fixed in:
6.7.0
Disclosed:
Jan 25, 2023

Mercado Pago payments for WooCommerce <= 6.6.0 - Cross-Site Request Forgery

medium

The Mercado Pago payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0. This is due to missing or incorrect nonce validation on the 'process_payment' function. This makes it possible for unauthenticated attackers to trick other users or visitors into checkin...

CVSS:
4.3
Affected:
up to 6.6.0
Fixed in:
6.7.0
Disclosed:
Jan 23, 2023

Mercado Pago payments for WooCommerce [woocommerce-mercadopago] < 6.7.0

unknown

The Mercado Pago payments for WooCommerce plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0. This is due to missing or incorrect nonce validation on the 'process_payment' function. This makes it possible for unauthenticated attackers to trick other users or visitors into checkin...

Affected:
up to 6.7.0
Fixed in:
6.7.0
Disclosed:
Jan 23, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database