Payment Gateway bKash for WC
Payment Gateway bKash for WC has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Payment Gateway bKash for WC has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Legion Hunter. Payment Gateway bKash for WC is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-62754Payment Gateway bKash for WC <= 3.1.0 - Missing Authorization
Read the full analysisVulnerability Records

Payment Gateway bKash for WC
Author
Kapil Paul
bKash PAYMENT METHOD FOR WOOCOMMERCE bKash Payment Method for WooCommerce enables seamless online payments for Bangladeshi merchants using the most popular mobile financial service bKash. This plugin allows your customers to pay securely and conveniently through bKash during checkout, providing a fast and trusted payment experience right from your WooCommerce store. With an easy setup process and full integration into WooCommerce’s checkout flow, this plugin is designed to make transactions smooth for both merchants and customers. ⭐ Key Features 🔐 Secure and reliable bKash payment integration ⚙️ Easy setup and configuration in WooCommerce settings 💸 Real-time transaction validation with the bKash API 🧾 Support for Refunds and Transaction Lookup 🎨 Fully compatible with the WooCommerce checkout page and themes 📱 Optimized for both desktop and mobile users Installation Guide After activate the plugin you need to go to Woocommerce settings for payments. Here you can see bKash as a payment method. Enable this and open settings for this payment method. Here you will see a link to go to the settings. (Or you may go to the bKash Settings from left menu). Collect your USERNAME, PASSWORD, APP_KEY, APP_SECRET from bKash. Place this in here and you are able to collect your payment. Test Mode In test mode, there are two options. One is with Test Credentials and another is without credentials. You may play with this plugin without giving any credentials. But when you need to generate document for bKash, you must need to fill up the necessary information. You can use the below information for a test transaction. bKash Wallet : 01770618575 bKash OTP : 123456 bKash PIN : 12121 Live Credentials Please provide necessary information here to receive live credentials: bKash NB: This link is not working anymore. You have to contact with your RM and request for the API access. They will provide it manually. Demo Video Why Choose This Plugin Bring the convenience of bKash — one of Bangladesh’s most trusted mobile payment platforms — directly to your WooCommerce store. Give your customers a smooth checkout experience, boost conversion rates, and simplify your payment process with a native bKash solution built specifically for WooCommerce. Privacy Policy Payment Gateway bKash for WC uses Appsero SDK to collect some telemetry data upon user’s confirmation. This helps us to troubleshoot problems faster & make product improvements. Appsero SDK does not gather any data by default. The SDK only starts gathering basic telemetry data when a user allows it via the admin notice. We collect the data to ensure a great user experience for all our users. Integrating Appsero SDK DOES NOT IMMEDIATELY start gathering data, without confirmation from users in any case. Learn more about how Appsero collects and uses this data. Contributing and Reporting Bugs Payment Gateway bKash for WC is being developed on GitHub. If you’re interested in contributing to the plugin, please look at Github page.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C