Input validation vulnerability in WooCommerce PensoPay 6.3.1

The WooCommerce PensoPay plugin for WordPress is vulnerable to a type of attack known as Reflected Cross-Site Scripting. This vulnerability affects versions up to and including 6.3.1, and it is caused by inadequate protection against unauthorised input and output. This means that if an attacker can trick a user into clicking on a link, they can inject malicious scripts into pages which will then be executed.

Detected in:

pensopay Payments fixed vulnerable versions:
WooCommerce PensoPay fixed vulnerable versions: >= * <= 6.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.