Piraeus Bank WooCommerce Payment Gateway
Piraeus Bank WooCommerce Payment Gateway has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (67%). Other recurring categories include SQL Injection.
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
3 independent researchers contributed these findings, one record each. Piraeus Bank WooCommerce Payment Gateway is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-73398Piraeus Bank WooCommerce Payment Gateway 3.2.0 - Missing Authorization
Read the full analysisVulnerability Records

Piraeus Bank WooCommerce Payment Gateway
Author
Papaki (Enartia S.A.)
This plugin adds Piraeus Bank paycenter as a payment gateway for WooCommerce. A contract between you and the Bank must be previously signed. Based on original plugin “Piraeus Bank Greece Payment Gateway for WooCommerce” by emspace.gr [https://wordpress.org/plugins/woo-payment-gateway-piraeus-bank-greece/] It uses the redirect method, and SSL is not required. Requires SOAP installed in the server / hosting. Important Notice Piraeus Bank has announced that it will gradually abolish the Preauthorized Payment Service for all merchants, beginning from the ones obtained MIDs from 29/1/2019 onwards. You are highly recommended to disable the preAuthorized Payment Service as soon as possible. We would like to inform you that our Plugin is compatible with the 3D Secure version 2 changes required from Piraeus bank. Features Provides pre-auth transactions and free instalments. HTTP Proxy In case your server doesn’t provide a static IP address for your website, you can use an HTTP Proxy for outgoing requests from the server to the bank. The following fields need to be filled for http proxying: HTTP Proxy Hostname: Required. If empty then HTTP Proxy is not used. HTTP Proxy Port: Required if HTTP Proxy Hostname is filled. HTTP Proxy Login Username/Password: Optional.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C