Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Ecommerce Fabrick vulnerabilities before they are exploited.

Vulnerability Records

3 records
Ecommerce Fabrick banner
Latestv20260604

Ecommerce Fabrick

Fabrick Support

Author

Fabrick Support

3.8(9)
76/100
Last Updated
2026-06-03 (2mo ago)
Active Installs
1,000+
Downloads
47,380
Requires WP
4.7+
Requires PHP
7.4+
Tested up to
WP 7.0.2
Created
2017-02-22 (10y ago)
Requires Plugins
woocommerce

Fabrick offers solutions to meet and anticipate payment acceptance needs across physical and digital channels. The offering is based on a single platform to accept payments through POS and e-commerce gateways, Banking-as-a-Service (BaaS), and omnichannel solutions that continuously evolve with market changes. With Fabrick Payment Orchestra, you can: * Accept payments from all major credit cards. * Accept payments with alternative methods, including PayPal, and manage them from a single dashboard. * Customize every aspect of the payment page. * Use a PCI DSS-compliant payment flow, without storing customers’ full credit card numbers on your servers. * Rely on 3DS2 support. Click here to read the full usage documentation on Fabrick. WooCommerce Blocks Compatibility The plugin is fully compatible with WooCommerce Blocks checkout. All payment methods are supported in both classic checkout and Blocks checkout modes. There is no need to disable WooCommerce Blocks checkout. Available Features S2S SOAP (except callReadTrxS2S and callVerifyCardS2S) Tokenization 3DS1 3DS2 – Authentication 3DS2 – Recurring Transactions RBA (Risk-Based Authentication) PayPal Seller Protection PayPal Billing Agreement WooCommerce Subscriptions support (Recurring payments and subscriptions) Available Payment Methods Credit Cards BANCOMAT Pay MyBank PayPal PayPal Billing Agreement PayPal Buy Now Pay Later Benefits Accept credit card payments directly on your checkout page. Accept payments with a variety of alternative methods to increase conversion by allowing customers to use their preferred payment option. Reduce fraud risk with advanced fraud detection tools (RBA). Security No full credit card data is stored on your servers during the payment process. All major card brands are supported (Visa, Mastercard, American Express). 3DS2.x support. Support You can contact our support team at ecommerce@sella.it. Actions and filters list Here is a list of filters and actions used in this plugin: Actions gestpay_before_processing_order gestpay_after_order_completed gestpay_after_order_failed gestpay_after_order_pending gestpay_before_order_settle gestpay_order_settle_success gestpay_order_settle_fail gestpay_before_order_refund gestpay_order_refund_success gestpay_order_refund_fail gestpay_before_order_delete gestpay_order_delete_success gestpay_order_delete_fail gestpay_after_s2s_order_failed gestpay_on_renewal_payment_failure gestpay_my_cards_template_before_table gestpay_my_cards_template_after_table Filters gestpay_gateway_parameters gestpay_encrypt_parameters gestpay_settings_tab gestpay_my_cards_template gestpay_cvv_fancybox gestpay_gateway_cards_images gestpay_alter_order_id -> this can be used to add, for example, a prefix to the order ID gestpay_revert_order_id -> this must be used to revert back the order ID changed with the gestpay_alter_order_id filter gestpay_s2s_validate_payment_fields gestpay_s2s_payment_fields_error_strings Third Party Libraries Questo plugin utilizza le seguenti librerie di terze parti: SOAP Client – Parte della libreria standard PHP, utilizzata per le comunicazioni con l’API Gestpay WooCommerce – Framework e-commerce per WordPress (GPLv3) WordPress – CMS principale (GPLv2 o successiva) jQuery – Libreria JavaScript per la manipolazione del DOM e la gestione degli eventi (MIT License) External services Questo plugin si connette ai seguenti servizi esterni: Axerve Payment Gateway (precedentemente Gestpay) – Scopo: Elaborazione dei pagamenti tramite il gateway di Banca Sella – Dati inviati: Informazioni sull’ordine, dati del cliente necessari per il pagamento – Quando: Durante il processo di pagamento e per le operazioni di gestione degli ordini – Privacy Policy: https://www.axerve.com/privacy-policy – Termini di servizio: https://www.axerve.com/terms-conditions icanhazip.com – Scopo: Identificazione dell’indirizzo IP del server per la configurazione del gateway di pagamento – Dati inviati: Nessun dato viene inviato, il servizio risponde solo con l’indirizzo IP pubblico – Quando: Solo nell’area amministrativa durante la configurazione del plugin – Privacy Policy: https://major.io/icanhazip-com-faq/ – Note: Questo servizio viene utilizzato solo per aiutare gli amministratori a configurare correttamente il gateway di pagamento nel backoffice di Axerve Script JavaScript di verifica – Scopo: Verifica della compatibilità del browser con il gateway di pagamento – Dati inviati: Informazioni sul browser dell’utente per verificare la compatibilità TLS – Quando: Durante il processo di pagamento – Domini: gestpay.net, gestpay.it, ecomm.sella.it – Privacy Policy: https://www.axerve.com/privacy-policy MyBank – Scopo: Integrazione con il sistema di pagamento MyBank – Dati inviati: Informazioni necessarie per il pagamento tramite MyBank – Quando: Solo quando l’utente sceglie MyBank come metodo di pagamento – Privacy Policy: https://www.mybank.eu/privacy-policy/ – Termini di servizio: https://www.mybank.eu/terms-and-conditions/ Server di test e sviluppo Nel codice di esempio (directory sample/) sono presenti riferimenti a domini fittizi (site1.it e site2.it) utilizzati solo come esempio per dimostrare la configurazione multi-sito. Questi domini sono puramente dimostrativi e non sono utilizzati nel codice di produzione.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C