Pagopar – WooCommerce Gateway

Pagopar – WooCommerce Gateway has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Pagopar – WooCommerce Gateway has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nguyen Xuan Chien. Pagopar – WooCommerce Gateway is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Pagopar – WooCommerce Gateway vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-31032

Pagopar – WooCommerce Gateway <= 2.7.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Pagopar – WooCommerce Gateway banner
Latestv2.8.13

Pagopar – WooCommerce Gateway

Pagopar - Grupo M S.A.

Author

Pagopar - Grupo M S.A.

3.0(2)
60/100
Last Updated
2025-07-11 (1y ago)
Active Installs
400+
Downloads
26,936
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2018-01-23 (9y ago)

Pagopar es una solución tecnológica que te permite cobrar con los principales medios de pago de Paraguay: tarjeta de crédito y débito locales (con las procesadoras Bancard, Cabal y Panal), tarjetas de crédito y débito internacionales, bocas de cobranza (Aqui Pago, Pago Express, Wepa) y billeteras electrónicas (Tigo Money, Personal, Zimple, Wally), transferencias bancarias y PIX para usuarios de Brasil.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C