OpenPix for WooCommerce

OpenPix for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for OpenPix for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Md. Moniruzzaman Prodhan (NomanProdhan). OpenPix for WooCommerce is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all OpenPix for WooCommerce vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-15400

OpenPix <= 2.13.3 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Read the full analysis

Vulnerability Records

1 records
OpenPix for WooCommerce banner
Latestv2.13.8

OpenPix for WooCommerce

sibeliusseraphini

Author

sibeliusseraphini

5.0(5)
100/100
Last Updated
2026-04-08 (5mo ago)
Active Installs
500+
Downloads
22,795
Requires WP
4.0+
Requires PHP
7.3+
Tested up to
WP 6.9.7
Created
2021-04-12 (6y ago)
Requires Plugins
woocommerce

The Pix Plugin for WooCommerce – OpenPix allows your customers to make payments using Pix within your online store, 24 hours a day, 7 days a week, via QR code or “copy and paste”. It’s practical, fast, and secure for both the customer and your store. Payment confirmation is done in real-time, which increases your e-commerce conversions and reduces costs with bank slips and credit cards. **ADVANTAGES OF THE PIX PLUGIN FOR WOOCOMMERCE – OPENPIX** Real-time update after payment More conversions Deposits via Pix to your business account One-click integration WebHook: Real-time payment notification More autonomy for charges and payments Chat support Unlimited transactions No monthly fees Free of bureaucracy Send via WhatsApp, Email and SMS Real-time Pix QR Code generation Pay only for received Pix Recurring billing and subscriptions Installment Pix Native anti-fraud at no additional cost Dashboard to track all transactions and bank reconciliation **START ACCEPTING PIX IN YOUR WOOCOMMERCE AND OFFER THE MOST PRACTICAL PAYMENT OPTION ON THE MARKET** 1 – Install the Pix WooCommerce – OpenPix plugin on your WordPress site 2 – Create an account at OpenPix Create account 3 – Copy the Client ID from your OpenPix account and click “Integrate with one click” Done! After these steps your online store can accept Pix payments If you need help you can talk to our support via chat or access the documentation. **FREQUENTLY ASKED QUESTIONS** DOES THE PLUGIN HAVE A COST OR MONTHLY FEE? No, the plugin is 100% free, you only pay a percentage of 0.8% per received Pix. WHAT CONFIGURATION IS REQUIRED TO USE THE PLUGIN? Have WordPress 4.0 or higher installed; Have WooCommerce plugin 3.0 or higher installed; Use PHP version 7.3 or higher; Have an active account at OpenPix CAN I USE THE PIX PLUGIN TOGETHER WITH OTHER PAYMENT GATEWAYS? Yes, the Pix plugin for WooCommerce – OpenPix can be used together with other complementary gateways such as card processors, bank slips, etc. WHERE ARE RECEIVED TRANSACTIONS DEPOSITED? Transactions are deposited directly to the Pix key linked to your business account every day. In the OpenPix dashboard, under “Accounts” you can customize deposit settings. HOW TO CONFIRM PAYMENT BY PIX? The Plugin automatically informs WooCommerce of the payment status, but if you need to verify and confirm a specific transaction just access your OpenPix dashboard under “Transactions”. Within the platform you will find all generated transactions and can view all details, make refunds and much more. SUPPORT For questions related to integration and plugin, access the OpenPix Developer Portal If you need to talk to our team, access the chat available on our website.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C