Pago por Redsys

Pago por Redsys has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Pago por Redsys has a vendor fix available, so running the current release closes it.

All of these findings were reported by José Aguilera. Pago por Redsys is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Pago por Redsys vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-12467

Pago por Redsys <= 1.0.12 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Pago por Redsys banner
Latestv1.0.14

Pago por Redsys

grafreak

Author

grafreak

5.0(8)
100/100
Last Updated
2025-02-20 (2y ago)
Active Installs
700+
Downloads
17,128
Requires WP
5.4+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2016-08-03 (10y ago)

REQUIRES TO HAVE TPV REDSYS CODES WITH YOUR BANK With this plugin you can have a payment gateway on your website. Your customers can pay you through an online POS. The plugin sends the user to the Redsys payment gateway with the order number and the amount that the user dials or that you have pre-filled (you can see more in the FAQ)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C