Zoho Billing – Embed Payment Form

Zoho Billing – Embed Payment Form has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

All of these findings were reported by Muhammad Yudha - DJ. Zoho Billing – Embed Payment Form is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Zoho Billing – Embed Payment Form vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2025-57963

Zoho Billing <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Zoho Billing – Embed Payment Form banner
Latestv4.1

Zoho Billing – Embed Payment Form

Zoho Subscriptions

Author

Zoho Subscriptions

2.0(4)
40/100
Last Updated
2025-11-30 (10mo ago)
Active Installs
400+
Downloads
16,425
Requires WP
0+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2015-09-08 (11y ago)

ZOHO BILLING PLUGIN FOR WORDPRESS This plugin allows you to embed a payment without any coding on your WordPress website. Your customers/visitors can make one-time and recurring payments to you using the embedded payment form. WHAT IS ZOHO BILLING? Zoho Billing is billing software that makes it easy to handle your customers’ entire billing life-cycle. It can help you with automated recurring billing, managing subscriptions, sending professional tax-compliant invoices, and getting paid on time, every time. You must to have an account with Zoho Billing to use this plugin, sign up now, if you haven’t already. Integration/Authentication Setup After installing and activating the plugin, you need to connect it to your Zoho Billing organization. To do this: Navigate to the Zoho Billing plugin from the Installed Plugins section in the left sidebar. Select the domain from which you access Zoho Billing. Enter the Connector Key from Zoho Billing. Tip: You can find your domain and the Connector Key by going to Zoho Billing > Settings > Integrations & Marketplace > Other Apps > WordPress Integration. Click the Save button EMBED PAYMENT FORMS You can embed your hosted payment pages from Zoho Billing by including the following shortcode while drafting (or editing) a page/post in WordPress: [zs plan_code="BASIC"] Copy and paste the shortcode above in WordPress’ editor. Next, replace BASIC in the shortcode with your plan’s actual Plan Code. You can see what your embedded hosted payment page looks like by previewing your page/post. Tip: You can find your plan’s Plan Code by going to Zoho Billing > Product Catalog > Subscription Items. Select a product and copy the Plan Code for the plan whose hosted payment pages you’d like to embed. You can adjust the width of your embedded hosted payment page by specifying a custom width in the shortcode above. Here’s how: [zs plan_code="BASIC" width="600"] Replace 600 in the shortcode above with your required width. If you do not include the “width” parameter, the default width will be set as 700. Learn more about the Zoho Billing plugin from our help document. WHO DO I CONTACT FOR MORE INFORMATION? You can reach out to our support team at support@zohobilling.com with any questions you have about this plugin and we’d be happy to assist you.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C