Xendit Payment
Xendit Payment has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (100%).
Every one of the 2 issues recorded for Xendit Payment has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Xendit Payment is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-66473Xendit Payment <= 7.2.0 - Missing Authorization
Read the full analysisVulnerability Records
Xendit Payment
Author
Xendit
woocommercePlease see our Documentation for full details. WooCommerce and WordPress enable you to build a fully fledged eCommerce platform. They are hosted and run entirely by merchants in their environment of choice. To enrich the eCommerce experience, Xendit-WooCommerce plugin allows secure online payment on your WooCommerce store. This enables you to accept various payments via Xendit with just a few clicks. 2,000+ installations IDR/PHP/USD/VND/THB/MYR acceptance Accept all the most popular payment methods on your WooCommerce Store Supports subscriptions via credit cards with WooCommerce Subscriptions plugin SMS, WhatsApp and email customer notifications 3DS Credit Card verification XenPlatform Support Flexible payment page redirection after checkout Installation Overview Please view our documentation for full installation instructions Download our plugin from the WordPress plug-in store Connect to Xendit, and activate your desired payment channels Start selling! Requirements WordPress: 4.9.16 or above WooCommerce: 3.3.3 or above PHP 7.0 or above Enable CUrl with OpenSSL by your web hosting provider Remove IP Whitelisting from you WooCommerce dashboard
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C