Pagopar – WooCommerce Gateway
Pagopar – WooCommerce Gateway has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Pagopar – WooCommerce Gateway has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Xuan Chien. Pagopar – WooCommerce Gateway is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-31032Pagopar – WooCommerce Gateway <= 2.7.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Pagopar – WooCommerce Gateway
Author
Pagopar - Grupo M S.A.
Pagopar es una solución tecnológica que te permite cobrar con los principales medios de pago de Paraguay: tarjeta de crédito y débito locales (con las procesadoras Bancard, Cabal y Panal), tarjetas de crédito y débito internacionales, bocas de cobranza (Aqui Pago, Pago Express, Wepa) y billeteras electrónicas (Tigo Money, Personal, Zimple, Wally), transferencias bancarias y PIX para usuarios de Brasil.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C