| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-31843 | Для национальных платежных систем в Узбекистане 安全漏洞 | goodoneuz | pay-uz | Critical | 9.8 | 2026-04-16 13:02:56 | Deep Dive |
| CVE-2026-33661 | WeChat Pay callback signature verification bypassed when Host header is localhost | yansongda | pay | High | 8.6 | 2026-03-26 21:05:23 | Deep Dive |
| CVE-2026-24601 | WordPress Penci Pay Writer plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability | PenciDesign | Penci Pay Writer | Medium | 6.5 | 2026-01-23 14:29:03 | Deep Dive |
| CVE-2025-68905 | WordPress JNews - Pay Writer plugin <= 11.0.0 - Local File Inclusion vulnerability | jegtheme | JNews - Pay Writer | - | - | 2026-01-22 16:52:14 | Deep Dive |
| CVE-2025-14450 | Wallet System for WooCommerce <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation | wpswings | Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments | Medium | 6.5 | 2026-01-17 02:22:32 | Deep Dive |
| CVE-2025-9322 | Stripe Payment Forms <= 8.3.1 - Unauthenticated SQL Injection | themeisle | Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions | High | 7.5 | 2025-10-25 06:49:23 | Deep Dive |
| CVE-2025-10992 | roncoo roncoo-pay lookupList improper authorization | roncoo | roncoo-pay | Medium | 5.3 | 2025-09-26 01:32:08 | Deep Dive |
| CVE-2025-10288 | roncoo roncoo-pay list improper authentication | roncoo | roncoo-pay | Medium | 5.3 | 2025-09-12 05:02:08 | Deep Dive |
| CVE-2025-10287 | roncoo roncoo-pay orderQuery direct request | roncoo | roncoo-pay | Low | 3.1 | 2025-09-12 04:32:07 | Deep Dive |
| CVE-2025-58616 | WordPress Frisbii Pay Plugin <= 1.8.2.1 - Broken Access Control Vulnerability | Frisbii | Frisbii Pay | Medium | 6.5 | 2025-09-03 14:36:48 | Deep Dive |
| CVE-2025-52580 | Gift Pad region PAY 日志信息泄露漏洞 | Gift Pad Co.,Ltd. | "region PAY" App for Android | 低危 | - | 2025-07-22 04:49:33 | Deep Dive |
| CVE-2025-4130 | Hardcoded Credentials in PAVO Inc.'s PAVO Pay | PAVO Inc. | PAVO Pay | High | 7.5 | 2025-07-21 14:01:07 | Deep Dive |
| CVE-2025-4129 | IDOR in PAVO Inc.'s PAVO Pay | PAVO Inc. | PAVO Pay | High | 7.5 | 2025-07-21 13:59:38 | Deep Dive |
| CVE-2025-52777 | WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Cross Site Scripting (XSS) Vulnerability | cmsMinds | Pay with Contact Form 7 | High | 7.1 | 2025-07-16 11:27:56 | Deep Dive |
| CVE-2025-24772 | WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Cross Site Request Forgery (CSRF) Vulnerability | cmsMinds | Pay with Contact Form 7 | Medium | 5.4 | 2025-06-06 12:54:39 | Deep Dive |
| CVE-2025-32126 | WordPress Pay with Contact Form 7 Plugin <= 1.0.4 - SQL Injection vulnerability | cmsMinds | Pay with Contact Form 7 | High | 7.6 | 2025-04-04 15:58:25 | Deep Dive |
| CVE-2025-23543 | WordPress FOMO Pay Chinese Payment Solution plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) vulnerability | fomopay | FOMO Pay Chinese Payment Solution | High | 7.1 | 2025-03-26 14:24:14 | Deep Dive |
| CVE-2024-55989 | WordPress WP Simple Pay Lite Manager Plugin <= 1.4 - SQL Injection vulnerability | Kyle M Brown | WP Simple Pay Lite Manager | High | 7.6 | 2024-12-16 14:13:39 | Deep Dive |
| CVE-2024-51918 | WordPress Pay With Stripe plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability | Freshlight Lab | Pay With Stripe | Medium | 6.5 | 2024-11-19 16:30:59 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |