VYPR

PhonePe Payment Solutions

by WordPress

CVEs (2)

  • CVE-2022-45835MedNov 13, 2023
    risk 0.41cvss 5.8epss 0.38

    Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

  • CVE-2026-11575HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces…