PayHere Payment Gateway
PayHere Payment Gateway has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for PayHere Payment Gateway has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. PayHere Payment Gateway is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-15475PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated Order Status Modification
Read the full analysisVulnerability Records

PayHere Payment Gateway
Author
PayHere
PayHere is a Sri Lankan Payment Gateway Service that enables you to accept payments online from your customers via Visa, MasterCard, Amex, eZcash, mCash & Internet Banking services. You can install this plugin to list PayHere as a payment method in your WooCommerce store.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C