Conekta Payment Gateway

Conekta Payment Gateway has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).

The one issue recorded for Conekta Payment Gateway has a vendor fix available, so running the current release closes it.

All of these findings were reported by dodoh4t. Conekta Payment Gateway is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Conekta Payment Gateway vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-49066

Conekta Payment Gateway <= 6.0.0 - Unauthenticated Information Exposure

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv6.2.1

Conekta Payment Gateway

Conekta Group

Author

Conekta Group

3.5(6)
70/100
Last Updated
2026-08-11 (4d ago)
Active Installs
2,000+
Downloads
110,804
Requires WP
6.1+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2017-06-07 (9y ago)

Current version features: Unified API Key Integration: Streamlines the integration procedure for all existing payment modalities under one cohesive set of API Keys. Refined Checkout Workflow: Enhances the user experience by consolidating checkout stages. Incorporates a robust checkpoint system to streamline transactions Enhanced Security with Conekta’s PCI-Certified Component: Elevate transaction protection using our secure, PCI-certified Conekta Component, designed to ensure a safe checkout experience 3D Secure Version 2 Support: Ensures compatibility with the latest 3DS v2 specification, aligning with current security norms and enhancing fraud prevention measures Automatic order status management Email notifications on successful purchase

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C