PayHere Payment Gateway

PayHere Payment Gateway has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for PayHere Payment Gateway has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. PayHere Payment Gateway is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all PayHere Payment Gateway vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-15475

PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated Order Status Modification

Read the full analysis

Vulnerability Records

2 records
PayHere Payment Gateway banner
Latestv2.4.5

PayHere Payment Gateway

PayHere

Author

PayHere

4.5(8)
90/100
Last Updated
2026-05-20 (4mo ago)
Active Installs
2,000+
Downloads
57,261
Requires WP
6.4+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2016-07-14 (10y ago)

PayHere is a Sri Lankan Payment Gateway Service that enables you to accept payments online from your customers via Visa, MasterCard, Amex, eZcash, mCash & Internet Banking services. You can install this plugin to list PayHere as a payment method in your WooCommerce store.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C