Payment Gateways Caller for WP e-Commerce

Payment Gateways Caller for WP e-Commerce has one disclosed vulnerability in the WordSec catalog, all reported in 2013; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).

The one issue recorded for Payment Gateways Caller for WP e-Commerce has a vendor fix available, so running the current release closes it.

All of these findings were reported by k3170makan. The current release is tested up to WordPress 3.7.41.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Payment Gateways Caller for WP e-Commerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8

Payment Gateways Caller for WP e-Commerce < 0.1.1 - Local File Inclusion

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.0.1

Payment Gateways Caller for WP e-Commerce

Andrés Villarreal

Author

Andrés Villarreal

0.0(0)
0/100
Last Updated
2014-02-14 (13y ago)
Active Installs
0+
Downloads
1,713
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 3.7.41
Created
2013-10-22 (13y ago)

This WordPress plugin for WP-E-Commerce allows to include a merchant file through a GET request without specifying its whole URL. Just call http://yoursite.com/?load_merchant=filename, without the .php extension, and you’re done. Please note that these requests cannot be used to display pages. Very important: Though this plugin avoids Local File Inclusion vulnerability, it is not responsible for the processes that are executed inside your gateway files. Before using it, you should be very sure that all your custom gateways are secure and will not perform any unwanted modifications or deletions of sensitive data.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C