Visa Acceptance Solutions

Visa Acceptance Solutions has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Authentication Bypass Using An Alternate Path Or Channel, behind 1 of the records (100%).

The one issue recorded for Visa Acceptance Solutions has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by 0xd4rk5id3. Visa Acceptance Solutions is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Visa Acceptance Solutions vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2026-3461

Visa Acceptance Solutions <= 2.1.0 - Unauthenticated Authentication Bypass via Billing Email

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.2.2

Visa Acceptance Solutions

Visa Acceptance Solutions

Author

Visa Acceptance Solutions

0.0(0)
0/100
Last Updated
2026-06-19 (2mo ago)
Active Installs
10,000+
Downloads
97,378
Requires WP
6.9+
Requires PHP
8.2.0+
Tested up to
WP 7.0.4
Created
2025-06-09 (1y ago)
Requires Plugins
woocommerce

This plugin integrates Visa Acceptance Solutions into your WooCommerce store, offering multiple payment methods such as Card Payments, Apple Pay, Google Pay, Click to Pay, Paze, and eCheck/ACH. Securely store customer payment details with our Token Management Services. Utilize Cybersource’s fraud prevention services to process transactions safely. Compatible with WooCommerce Subscriptions Privacy Policy and Terms of Service Refer to Terms of Service Refer to Privacy Policy Admin Notice Version 2.2.2 is now available. Please refer to change log for details.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C