The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Project Subscriptions

Vendors Products
Evertec Subscribe
Woocommerce Placetopay Gateway Subscribe
Woocommerce Placetopay Gateway Belice Subscribe
Woocommerce Placetopay Gateway Colombia Subscribe
Woocommerce Placetopay Gateway Ecuador Subscribe
Woocommerce Placetopay Gateway Honduras Subscribe
Woocommerce Placetopay Gateway Uruguay Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Evertec
Evertec woocommerce Placetopay Gateway
Evertec woocommerce Placetopay Gateway Belice
Evertec woocommerce Placetopay Gateway Colombia
Evertec woocommerce Placetopay Gateway Ecuador
Evertec woocommerce Placetopay Gateway Honduras
Evertec woocommerce Placetopay Gateway Uruguay
Wordpress
Wordpress wordpress
Vendors & Products Evertec
Evertec woocommerce Placetopay Gateway
Evertec woocommerce Placetopay Gateway Belice
Evertec woocommerce Placetopay Gateway Colombia
Evertec woocommerce Placetopay Gateway Ecuador
Evertec woocommerce Placetopay Gateway Honduras
Evertec woocommerce Placetopay Gateway Uruguay
Wordpress
Wordpress wordpress

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Description The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-17T18:05:42.895Z

Reserved: 2026-06-04T22:10:12.885Z

Link: CVE-2026-11324

cve-icon Vulnrichment

Updated: 2026-07-17T12:35:17.864Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T22:09:28Z

Weaknesses