GlobalPayments Gateway Provider for WooCommerce
GlobalPayments Gateway Provider for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Server-Side Request Forgery (SSRF).
Every one of the 2 issues recorded for GlobalPayments Gateway Provider for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. GlobalPayments Gateway Provider for WooCommerce is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2026-39645GlobalPayments WooCommerce <= 1.18.3 - Unauthenticated Server-Side Request Forgery
Read the full analysisVulnerability Records
GlobalPayments Gateway Provider for WooCommerce
Author
Global Payments
woocommerceThis extension allows WooCommerce to use the available Global Payments payment gateways. All card data is tokenized using the respective gateway’s tokenization service. Features Heartland Portico gateway Global Payments Genius gateway Global Payments TransIT gateway with TSEP Unified Payments Credit Cards Integrates with Woocommerce Sale transactions (automatic capture or separate capture action later) Refund transactions from a previous Sale Stored payment methods 3D Secure 2 & SCA Digital Wallets – Google Pay Digital Wallets – Apple Pay Digital Wallets – Click To Pay Payments over the phone Buy Now Pay Later – Affirm Buy Now Pay Later – Clearpay Buy Now Pay Later – Klarna Bank Payment PayPal Support For more information or questions, please email developers@globalpay.com . Developer Docs Discover our developer portal powered by Heartland, a Global Payments Company (https://developer.heartlandpaymentsystems.com/) or our portal for companies located outside the US (https://developer.globalpay.com/). Unified Payments Sandbox credentials Access to our Unified Payments requires sandbox credentials which you can retrieve yourself via our Developer Portal: First go to the Developer Portal. Click on the person icon in the top-right corner and select Log In or Register. Once registered, click on the person icon again and select Unified Payments Apps. Click ‘Create a New App’. An app is a set of credentials used to access the API and generate access tokens.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C