The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Evertec
Evertec woocommerce Placetopay Gateway
Evertec woocommerce Placetopay Gateway Belice
Evertec woocommerce Placetopay Gateway Colombia
Evertec woocommerce Placetopay Gateway Ecuador
Evertec woocommerce Placetopay Gateway Honduras
Evertec woocommerce Placetopay Gateway Uruguay
Wordpress
Wordpress wordpress
Vendors & Products Evertec
Evertec woocommerce Placetopay Gateway
Evertec woocommerce Placetopay Gateway Belice
Evertec woocommerce Placetopay Gateway Colombia
Evertec woocommerce Placetopay Gateway Ecuador
Evertec woocommerce Placetopay Gateway Honduras
Evertec woocommerce Placetopay Gateway Uruguay
Wordpress
Wordpress wordpress

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Description The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2026-07-17T02:31:31.888Z

Updated: 2026-07-17T18:05:42.895Z

Reserved: 2026-06-04T22:10:12.885Z

Link: CVE-2026-11324

cve-icon Vulnrichment

Updated: 2026-07-17T12:35:17.864Z

cve-icon NVD

No data.

cve-icon Redhat

No data.