SMEPay: UPI Gateway for WooCommerce

SMEPay: UPI Gateway for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for SMEPay: UPI Gateway for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Alexis Lafontaine. SMEPay: UPI Gateway for WooCommerce is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all SMEPay: UPI Gateway for WooCommerce vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-66461

SMEPay: UPI Gateway for WooCommerce <= 1.0.5 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
SMEPay: UPI Gateway for WooCommerce banner
Latestv1.0.5

SMEPay: UPI Gateway for WooCommerce

smepay

Author

smepay

5.0(4)
100/100
Last Updated
2025-11-16 (9mo ago)
Active Installs
100+
Downloads
1,943
Requires WP
4.7+
Requires PHP
7.0+
Tested up to
WP 6.8.8
Created
2025-07-08 (1y ago)
Requires Plugins
woocommerce

SMEPay: UPI Gateway for WooCommerce is a WordPress plugin built specifically for Indian WooCommerce stores to accept payments via UPI QR codes. With SMEPay, customers can scan a QR code at checkout to make instant payments using popular UPI apps like Google Pay, PhonePe, or Paytm. The plugin is easy to install, configure, and fully compatible with the latest WooCommerce versions. Features: UPI Payments Integration: Accept UPI payments via QR code. Works with WooCommerce: Seamless integration with WooCommerce. Customizable Settings: Configure title, description, and more directly from the WooCommerce settings page. Instant Payment: Customers can complete transactions with instant UPI payment processing. Requirements SSL Certificate Required: For secure payment processing, your website must have an SSL certificate (HTTPS) installed and configured. Verify SSL by checking for the padlock icon in your browser’s address bar. If you don’t have SSL, please obtain one from your hosting provider before enabling SMEPay. External Services This plugin connects to the SMEPay platform, a third-party UPI payment service provided by Typof Technologies, to enable UPI payments in your WooCommerce store. 🔧 API Endpoints (Based on Mode) The plugin uses different endpoints depending on your selected mode: Development Mode (mode = development): Base URL: https://staging.smepay.in/api/wiz/… Production Mode (mode = production): Base URL: https://extranet.smepay.in/api/wiz/… Endpoints Used: /external/auth – Authenticate WooCommerce store with SMEPay /external/create-order – Create UPI QR payment request /external/validate-order – Validate payment status Frontend Widget Script: https://typof.co/smepay/checkout-v2.js – This script loads a React-based frontend app that renders the UPI QR code at checkout. It enables customers to scan and pay using their UPI app. It only uses data required to generate and display the QR code for the current WooCommerce order. It does not track users, store cookies, or collect personal data outside the transaction context. 📤 Data Shared with SMEPay During payment processing, the plugin sends: – WooCommerce order ID, total amount, currency – Customer info (name, email, phone) – Callback URL (order confirmation page) – SMEPay Client ID & Secret – Mode indicator (development or production) 🛡️ Data Sharing Consent No data is sent to SMEPay unless the customer explicitly selects the SMEPay payment option at checkout and places an order. 🔄 When Data Is Sent When the user selects SMEPay at checkout and the order is created After payment, to confirm successful payment via the validate endpoint ⚙️ Why We Send This Data To generate a transaction-specific UPI QR code To confirm payment and update order status in WooCommerce To ensure secure, authenticated communication linked to your store If the SMEPay service is temporarily unavailable, customers can select an alternative payment method configured in your WooCommerce store. 🧭 Service Provider Details This plugin interacts with the following SMEPay-hosted domains: – smepay.in, typof.co – API endpoints – typof.co – QR widget script (checkout-v2.js) Service Provider: SMEPay by Typof Technologies – Terms of Service – Privacy Policy

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C