Payment Gateways Caller for WP e-Commerce
Payment Gateways Caller for WP e-Commerce has one disclosed vulnerability in the WordSec catalog, all reported in 2013; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).
The one issue recorded for Payment Gateways Caller for WP e-Commerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by k3170makan. The current release is tested up to WordPress 3.7.41.
Payment Gateways Caller for WP e-Commerce < 0.1.1 - Local File Inclusion
Read the full analysisVulnerability Records
Payment Gateways Caller for WP e-Commerce
Author
Andrés Villarreal
This WordPress plugin for WP-E-Commerce allows to include a merchant file through a GET request without specifying its whole URL. Just call http://yoursite.com/?load_merchant=filename, without the .php extension, and you’re done. Please note that these requests cannot be used to display pages. Very important: Though this plugin avoids Local File Inclusion vulnerability, it is not responsible for the processes that are executed inside your gateway files. Before using it, you should be very sure that all your custom gateways are secure and will not perform any unwanted modifications or deletions of sensitive data.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C