All 6 CVE vulnerabilities found in PayPlus Payment Gateway, with AI-generated Chinese analysis, references, and POCs.
Vendor: PayPlus LTD
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-93620 | WordPress PayPlus Payment Gateway plugin <= 8.2.5 - Broken Access Control vulnerability CWE-862 | 6.5 | Medium | 2026-09-23 |
| CVE-2026-12972 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering | - | - | 2026-07-20 |
| CVE-2026-12973 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification | - | - | 2026-07-20 |
| CVE-2024-37459 | WordPress PayPlus Payment Gateway plugin <= 6.6.8 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2024-07-21 |
| CVE-2024-6205 | PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi | 9.8 | - | 2024-07-19 |
| CVE-2024-37564 | WordPress PayPlus Payment Gateway plugin <= 7.0.7 - SQL Injection vulnerability CWE-89 | 8.5 | High | 2024-07-12 |
All 6 known CVE vulnerabilities affecting PayPlus Payment Gateway with full Chinese analysis, references, and POCs where available.