Skrill – WooCommerce
Skrill – WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Skrill – WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Skalucy. Skrill – WooCommerce is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-28876Skrill Official <= 1.0.66 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
Skrill – WooCommerce
Author
Skrill_Team
Skrill Merchant On Boarding: Secure online payments for your business. Take advantage of a modern, flexible, and optimized payment solution- all with one contract, one integration and free setup. What this module does for you: Free and quick setup Access credit cards, 20+ local payment methods and support for over 80 banks Take advantage of the Skrill multi-currency account, giving you access to 40+ currencies High-security standards and anti-fraud technology Seamless payment experience across mobile, tablet and desktop Connect with millions of Skrill account holders Features: Additional payment options and control over how they are displayed Instant settlement Enhanced reporting and transaction status viewing Refund capability within Woocommerce What your customers will like: Easy ways to pay safely online – no sign-up required to make payments Convenient and immediate payments – pay with debit and credit cards or with a bank account, without any hassle Multiple local payment options allowing customers to pay how they want Internationally recognised and trusted brand The Skrill fee structure is a competitive 1.9%+0.29 EUR and 1%+0.29 EUR for Instant bank transfer. *Fees apply to new merchants only. Don’t have an account? Sign up for free today!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C