Klamra Paycal for Aspaclaria

Klamra Paycal for Aspaclaria has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).

The one issue recorded for Klamra Paycal for Aspaclaria has a vendor fix available, so running the current release closes it.

All of these findings were reported by KEVIN LEE (crattack). The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Klamra Paycal for Aspaclaria vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2026-8611

Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'invoice_id' Parameter

Read the full analysis

Vulnerability Records

1 records
Klamra Paycal for Aspaclaria banner
Latestv1.3.0

Klamra Paycal for Aspaclaria

klamra22

Author

klamra22

0.0(0)
0/100
Last Updated
2026-06-25 (2mo ago)
Active Installs
0+
Downloads
1,155
Requires WP
6.0+
Requires PHP
8.0+
Tested up to
WP 7.0.4
Created
2026-02-25 (6mo ago)

PayCal is a branded checkout and payment-management platform for WooCommerce stores built for creative businesses. The plugin connects a merchant’s WooCommerce store to PayCal Platform, where WooCommerce checkout, hosted checkout sessions, merchant settings, License Token validation and approved payment-provider connections are managed. Features Connect WooCommerce checkout to PayCal Prepare Apple Pay and hosted checkout experiences Use PayCal branded hosted checkout Manage merchant connection and License Token validation Connect to approved payment-provider configurations Support payment-management workflows for creative businesses PayCal helps merchants manage checkout and payment context. It does not replace the merchant’s payment provider, does not act as a bank or seller of record, and does not store card details. PayCal Connector This version is the customer-side connector. Merchant and terminal administration is handled in the PayCal platform. Hosted Checkout Gateway Version 1.3.0 includes the customer-side hosted WooCommerce gateway. Apple Pay provisioning remains in PayCal Platform and is synced by Merchant ID, Terminal ID, Public Key and Token.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C