VYPR

Payment Gateway for Redsys & WooCommerce Lite

by WordPress

CVEs (2)

  • CVE-2026-12584HigAug 6, 2026
    risk 0.49cvss 7.5epss

    The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a…

  • CVE-2026-5050HigApr 16, 2026
    risk 0.42cvss 7.5epss 0.00

    The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 7.0.0 due to successful_request() handlers calculating a local signature but not validating Ds_Signature…