Pago por Redsys
Pago por Redsys has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Pago por Redsys has a vendor fix available, so running the current release closes it.
All of these findings were reported by José Aguilera. Pago por Redsys is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-12467Pago por Redsys <= 1.0.12 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Pago por Redsys
Author
grafreak
REQUIRES TO HAVE TPV REDSYS CODES WITH YOUR BANK With this plugin you can have a payment gateway on your website. Your customers can pay you through an online POS. The plugin sends the user to the Redsys payment gateway with the order number and the amount that the user dials or that you have pre-filled (you can see more in the FAQ)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C