Piraeus Bank WooCommerce Payment Gateway

Piraeus Bank WooCommerce Payment Gateway has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2026 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 2 of the records (67%). Other recurring categories include SQL Injection.

2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

3 independent researchers contributed these findings, one record each. Piraeus Bank WooCommerce Payment Gateway is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage67%
Open

1

Fixed

2

Get automatic notifications for all Piraeus Bank WooCommerce Payment Gateway vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-73398

Piraeus Bank WooCommerce Payment Gateway 3.2.0 - Missing Authorization

Read the full analysis

Vulnerability Records

3 records
Piraeus Bank WooCommerce Payment Gateway banner
Latestv3.2.0

Piraeus Bank WooCommerce Payment Gateway

Papaki (Enartia S.A.)

Author

Papaki (Enartia S.A.)

3.9(35)
78/100
Last Updated
2026-01-19 (8mo ago)
Active Installs
3,000+
Downloads
72,355
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2017-03-22 (10y ago)

This plugin adds Piraeus Bank paycenter as a payment gateway for WooCommerce. A contract between you and the Bank must be previously signed. Based on original plugin “Piraeus Bank Greece Payment Gateway for WooCommerce” by emspace.gr [https://wordpress.org/plugins/woo-payment-gateway-piraeus-bank-greece/] It uses the redirect method, and SSL is not required. Requires SOAP installed in the server / hosting. Important Notice Piraeus Bank has announced that it will gradually abolish the Preauthorized Payment Service for all merchants, beginning from the ones obtained MIDs from 29/1/2019 onwards. You are highly recommended to disable the preAuthorized Payment Service as soon as possible. We would like to inform you that our Plugin is compatible with the 3D Secure version 2 changes required from Piraeus bank. Features Provides pre-auth transactions and free instalments. HTTP Proxy In case your server doesn’t provide a static IP address for your website, you can use an HTTP Proxy for outgoing requests from the server to the bank. The following fields need to be filled for http proxying: HTTP Proxy Hostname: Required. If empty then HTTP Proxy is not used. HTTP Proxy Port: Required if HTTP Proxy Hostname is filled. HTTP Proxy Login Username/Password: Optional.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C