Fortis for WooCommerce

Fortis for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10. 2026 was the busiest year with 2 disclosures.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Fortis for WooCommerce has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Fortis for WooCommerce is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Fortis for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-15609

Fortis for WooCommerce < 1.3.1 - Unauthenticated Information Exposure

Read the full analysis

Vulnerability Records

2 records
Fortis for WooCommerce banner
Latestv1.3.3

Fortis for WooCommerce

Fortis

Author

Fortis

0.0(0)
0/100
Last Updated
2026-09-09 (4d ago)
Active Installs
300+
Downloads
6,523
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2024-10-14 (2y ago)

The Fortis plugin for WooCommerce lets you accept online payments including credit cards, debit cards and ACH. Features: 1. Embedded payments iframe on the checkout page 2. ACH and CC payment methods supported 3. Level 2 and Level 3 processing supported for interchange optimization 3.1 To make use of this function, you will need to add the following product attributes to each product: commodity_code e.g. cc123456 unit_code e.g. gll 4. Webhooks for ACH status update on Settlement 5. Logged-in customers can store CC and ACH details to use for future payments 6. Refund and Void from the Order screen 7. Sandbox mode for testing 8. Customizable payments iframe appearance with two different view options 9. Compatible with WooCommerce Blocks About Fortis Fortis delivers comprehensive payment solutions and commerce enablement to software partners and developers, processing billions of dollars annually. The company’s mission is to forge a holistic commerce experience, guiding businesses to reach uncharted growth and scale. Fortis for WooCommerce enables you to offer a seamless and secure payment experience for customers using your e-commerce store. Guest customers make payments via a secure and customizable payments iframe hosted by Fortis. Customers that create accounts have the option to store multiple payment cards to use for future payments that they can select on checkout for a seamless payment experience. Third Party services https://api.sandbox.fortis.tech https://api.fortis.tech https://js.sandbox.fortis.tech/commercejs-v1.0.0.min.js Service Terms https://fortispay.com/fortisplatform-serviceagreement/ Privacy Policy https://fortispay.com/privacy-policy/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C