WooCommerce GoCardless Gateway
WooCommerce GoCardless Gateway has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).
The one issue recorded for WooCommerce GoCardless Gateway has a vendor fix available, so running the current release closes it.
All of these findings were reported by Rafie Muhammad. WooCommerce GoCardless Gateway is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-37871WooCommerce GoCardless Gateway <= 2.5.6 - Unauthenticated Insecure Direct Object Reference
Read the full analysisVulnerability Records

GoCardless for WooCommerce
Author
GoCardless
woocommerceThis is a feature plugin for accepting payments via GoCardless. It requires WooCommerce to be installed before GoCardless for WooCommerce can be activated. Compatibility This extension is compatible with: Woo Subscriptions Test Account Setup You can create a user on gocardless.com for live transactions and on the sandbox for test transactions. When you first set up a site, you’ll be prompted to create a user for the correct GoCardless environment when setting up the webhooks. Development Install Dependencies & Build The plugin uses Webpack to build the assets. To build the assets, follow these steps: Run npm install to install the dependencies. Run npm run build:webpack to build the asset files. You can also run npm run start:webpack to watch the files and rebuild them automatically when they change. You can find the source files in the assets and client directories.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C