WooCommerce GoCardless Gateway

WooCommerce GoCardless Gateway has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.

The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).

The one issue recorded for WooCommerce GoCardless Gateway has a vendor fix available, so running the current release closes it.

All of these findings were reported by Rafie Muhammad. WooCommerce GoCardless Gateway is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WooCommerce GoCardless Gateway vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2023-37871

WooCommerce GoCardless Gateway <= 2.5.6 - Unauthenticated Insecure Direct Object Reference

Read the full analysis

Vulnerability Records

1 records
GoCardless for WooCommerce banner
Latestv3.0.2

GoCardless for WooCommerce

GoCardless

Author

GoCardless

5.0(1)
100/100
Last Updated
2026-08-26 (17d ago)
Active Installs
1,000+
Downloads
18,124
Requires WP
6.9+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2025-02-12 (2y ago)
Requires Plugins
woocommerce

This is a feature plugin for accepting payments via GoCardless. It requires WooCommerce to be installed before GoCardless for WooCommerce can be activated. Compatibility This extension is compatible with: Woo Subscriptions Test Account Setup You can create a user on gocardless.com for live transactions and on the sandbox for test transactions. When you first set up a site, you’ll be prompted to create a user for the correct GoCardless environment when setting up the webhooks. Development Install Dependencies & Build The plugin uses Webpack to build the assets. To build the assets, follow these steps: Run npm install to install the dependencies. Run npm run build:webpack to build the asset files. You can also run npm run start:webpack to watch the files and rebuild them automatically when they change. You can find the source files in the assets and client directories.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C