plugin

Yoco Payment Gateway Vulnerabilities

2 known security issues reported for the Yoco Payment Gateway WordPress plugin. Most recent disclosed Jan 6, 2026.

2 high

Running Yoco Payment Gateway on your site? Check whether your installed version is affected.

Scan your site free

Yoco Payments <= 3.9.0 - Unauthenticated Arbitrary File Read

high

The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via the file parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 3.9.0
Fixed in:
3.9.1
Disclosed:
Jan 6, 2026

CVE-2025-13801 on NVD →

Yoco Payments < 3.9.1 - Unauthenticated Arbitrary File Read

high
Affected:
up to 3.9.1
Fixed in:
3.9.1
Disclosed:
Jan 6, 2026

CVE-2025-13801 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database