iCount Payment Gateway
iCount Payment Gateway has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for iCount Payment Gateway has a vendor fix available, so running the current release closes it.
All of these findings were reported by ch4r0n. iCount Payment Gateway is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-53295iCount Payment Gateway <= 2.1.1 - Missing Authorization
Read the full analysisVulnerability Records

iCount Payment Gateway
Author
iCount
The iCount Payment Gateway allows users to connect their WooCommerce website to iCount accounting platform. This plugin facilitates two main objectives: 1. Accept credit card payments through iCount’s payment gateway. 2. Create invoices and receipts for each payment. Use of this plugin is subject to accepting iCount Terms Of Use External Services and Data Privacy This plugin communicates with iCount’s internal API (https://api.icount.co.il) to process payments and manage invoices. No third-party services other than iCount’s internal systems are used to handle data or transactions. API and Data Usage: The plugin uses the iCount API to transmit transaction data for payment processing and invoicing. All data is transmitted securely between your website and iCount’s servers. No data is sent to external services beyond the iCount system. Please refer to iCount’s Terms of Use and Privacy Policy for more information on how your data is handled. Features Credit Card Payments: Seamless integration with iCount’s CC gateway to accept credit card payments securely. Automated Invoicing: Automatically create invoices and receipts for each payment processed through the plugin. Easy Setup: Simple configuration and setup process within your WooCommerce store. Transaction Management: View and manage all transactions from your WooCommerce admin panel. Configuration Navigate to WooCommerce > Settings > Payments. Click on iCount Payments. Enter your iCount API Token. Save changes. Usage Once configured, the plugin will enable credit card payments through iCount’s CC gateway. Invoices and receipts will be automatically generated for each payment and can be viewed in your iCount account. Support If you have any questions or need assistance, please open a chat window from your iCount account: https://app.icount.co.il/support/new_ticket.php © iCount. All rights reserved. Visit iCount.co.il for more information.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C