Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical1
High0
Medium2
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-07-20

CVE-2026-12973 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.

PLUGIN Payplus Payment Gateway

CVE-2026-12973

MEDIUM CVSS 6.5 2026-07-20
Threat Entry Updated 2026-07-20

CVE-2026-12972 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.

PLUGIN Payplus Payment Gateway

CVE-2026-12972

MEDIUM CVSS 5.3 2026-07-20
Threat Entry Updated 2024-11-21

CVE-2024-6205 - Payplus Payment Gateway Plugin

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.

PLUGIN Payplus Payment Gateway

CVE-2024-6205

CRITICAL CVSS 9.8 2024-07-19
Scroll to top