payOS
payOS has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for payOS has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. payOS is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-57946payOS <= 1.0.61 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
payOS
Author
Loc Bui
woocommercepayOS is a powerful plugin that integrates the VietQR payment gateway into WooCommerce, allowing for “super-fast” payment processing. With payOS, a unique bank QR code is generated automatically for each order, streamlining the checkout process and improving customer satisfaction. Features: – Seamless integration with WooCommerce – Automatic VietQR code generation for each order – Faster checkout process with QR code payment – Compatible with multiple Vietnamese banks – Easy to set up and configure Dependency on Third-Party Services This plugin relies on the integration with the payOS payment gateway as a third-party service to function correctly. This requires the transmission of certain data to and from the payOS service. How the plugin uses payOS: When an order is placed on your WooCommerce store, this plugin automatically generates a VietQR code by sending the relevant order information to the payOS service. This QR code is then displayed to the customer to streamline the payment process. Links: payOS Merchant API payOS Checkout page payOS Terms of use payOS Privacy policy By using this plugin, you agree to the terms and conditions of the payOS service, including their privacy policy. We strongly advise that you review both the terms of use and the privacy policy to ensure compliance with relevant legal requirements. Please note that this usage is essential for the functionality of payOS. Full disclosure ensures transparency and allows users to make informed decisions regarding the use of this plugin and the transmission of their data.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C