Payment Gateway PayPay for WooCommerce

Payment Gateway PayPay for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Insufficient Verification Of Data Authenticity, behind 1 of the records (100%).

The one issue recorded for Payment Gateway PayPay for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Pedro Pinho. Payment Gateway PayPay for WooCommerce is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Payment Gateway PayPay for WooCommerce vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-82215

Payment Gateway PayPay for WooCommerce 0.5 - 0.9.3 - Unauthenticated Payment Bypass

Read the full analysis

Vulnerability Records

1 records
Payment Gateway PayPay for WooCommerce banner
Latestv0.9.3

Payment Gateway PayPay for WooCommerce

Hiroaki Miyashita

Author

Hiroaki Miyashita

0.0(0)
0/100
Last Updated
2026-09-04 (13d ago)
Active Installs
100+
Downloads
5,008
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2021-03-18 (6y ago)
Requires Plugins
woocommerce

The Payment Gateway PayPay for WooCommerce plugin adds the functionality to take PayPay payments on your store of WooCommerce. About PayPay PayPay is barcode based payment services in Japan. In order to start PayPay payments, you need to create a PayPay developer account. PayPay for Developers In order to make the mode Real, you have to purchase the authentication key at the following site. WordPress Market External services This plugin connects to the PayPay Open Payment API to create and manage payments. Order amounts, merchant-generated payment identifiers, and any optional order descriptions or items configured by the merchant may be sent to PayPay when a payment is created or managed. This service is provided by PayPay Corporation under its terms and privacy policy. When an administrator saves the gateway settings, the plugin connects to WordPress Market to validate the optional Authentication Key used to enable Real mode. The site’s domain and the entered Authentication Key are sent for this purpose. This service is provided by e-t net Inc. under the WordPress Market terms and privacy policy. Known Issues / Bugs Nothing. Uninstall Deactivate the plugin That’s it! 🙂

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C