Eway Payments for Woo
Eway Payments for Woo has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).
The one issue recorded for Eway Payments for Woo has a vendor fix available, so running the current release closes it.
Eway Payments for Woo is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
WooCommerce Eway Gateway <= 3.5.0 - Insecure Direct Object Reference
Read the full analysisVulnerability Records

Eway Payments for Woo
Author
ewaypayments
The Eway extension for WooCommerce allows you to take credit card payments directly on your store without redirecting your customers to a third party site to make payment. Supports WooCommerce Subscriptions, WooCommerce Refunds API, as well as token payments, which allows customers to save credit cards for future purchases. Everything happens on your site without the customer ever leaving. The Eway payment gateway for WooCommerce makes use of Eway’s brand new Rapid 3.1 API, it supports 3D Secure and is fully PCI compliant as per Eway’s specifications and adds support for processing subscription payments as well as token payments allowing customers to save credit cards for future purchases. By using Eway’s Rapid 3.1 API there is a single endpoint for processing payment, meaning you only need this one extension to take payment through any of Eway’s processing countries, Eway Australia, Eway New Zealand, Eway Singapore, Eway Malaysia, and Eway Hong Kong. Eway uses complex DNS technology to ensure your payment is routed to the correct country. Key Features Ability to host promotional flash sales in real-time Generate discount coupons for your customers to help with special promotions Product reviews from your customers Automatic up-sells and cross-sells Intuitive order management suite
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C