CorvusPay WooCommerce Payment Gateway

CorvusPay WooCommerce Payment Gateway has 4 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 4 are fixed as of August 2026. Their average CVSS score is 5.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 4 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Scripting, Improper Verification Of Cryptographic Signature.

Every one of the 4 issues recorded for CorvusPay WooCommerce Payment Gateway has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (3) reported by Valatty. CorvusPay WooCommerce Payment Gateway is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 0.

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all CorvusPay WooCommerce Payment Gateway vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-6939

CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter

Read the full analysis

Vulnerability Records

4 records
CorvusPay WooCommerce Payment Gateway banner
Latestv2.7.6

CorvusPay WooCommerce Payment Gateway

corvuspay

Author

corvuspay

0.0(0)
0/100
Last Updated
2026-07-17 (1mo ago)
Active Installs
1,000+
Downloads
32,027
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 0
Created
2015-05-19 (11y ago)

CorvusPay is a flexible, maximally reliable and a highly available Internet Payment Gateway service for card payments in web shops, verified through millions of transactions processed for hundreds of merchants in Croatia and the region! How does the CorvusPay service help you grow your business? No matter if your company is small, medium-sized or large, if it sells products or services, in today’s age of ubiquitous digitalisation selling through online channels is a must. In order to sell anything online, one must offer various payment methods, including card payments which allow: selling through a shopping basket system or payment link generators, 24/7/365 sales to buyers across the globe, secure collection of payments in real time and multiple currencies, convenient installment payments. Security comes first! The Payment Card Industry Data Security Standard (PCI DSS) is the highest information security standard for organisations which store, process or transfer payment card and cardholder data. It has been defined by the largest card schemes on a global level. CorvusPay has held a PCI DSS Level 1 certificate since 2012 and renews it successfully every year! Why is security our biggest investment? To protect our buyers against personal and card data theft! To help merchants build buyer loyalty for their web shops! Support for popular payment card brands! CorvusPay offers support for all popular payment card brands: MasterCard, Maestro, Visa, American Express, Diners and Discover. CorvusWallet FASTER AND MORE SECURE ONLINE PAYMENTS AND PAYMENT COLLECTION! Once saved, payment card and cardholder data enable buyers to complete transactions faster and help merchants achieve better conversion rates. For additional information about CorvusWallet service, which is supported with the current version of plugin, please visit https://www.corvuspay.com/privatni/. If you want to enable CorvusWallet payment method in your web shop, please contact us on email info@corvuspay.com or phone +385 1 6389 441. For more info about CorvusPay please visit www.corvuspay.com.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C