Executive brief
The Placetopay and AvalPay payment gateway plugins for WordPress are vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. These plugins are used by online stores to process customer payments. If an attacker tricks a customer or administrator into clicking a malicious link, they could potentially steal session information or perform unauthorized actions on the victim's behalf.
Technical details
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'redirect-url' parameter. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a script payload and tricking a user into clicking it. When the victim visits the link, the malicious script executes within the context of their browser session. This can lead to the theft of sensitive information, such as session cookies, or the execution of unauthorized actions. The vulnerability affects all versions up to and including 3.2.2.
Affected products
- Evertec WooCommerce Placetopay Gateway Belice <= 3.2.2
- Evertec WooCommerce Placetopay Gateway Ecuador <= 3.2.2
- Evertec WooCommerce Placetopay Gateway Colombia <= 3.2.2
- Evertec WooCommerce Placetopay Gateway Uruguay <= 3.2.2
- Evertec WooCommerce Placetopay Gateway Honduras <= 3.2.2
- Evertec WooCommerce Placetopay Gateway <= 3.2.2
Timeline
- 2026-04-22: patched: Version 3.2.2 released (Note: Advisory states versions up to and including 3.2.2 are vulnerable)
- 2026-07-17: disclosed: CVE published
References
- https://banco.santander.cl/uploads/000/049/181/1705c2cf-fc73-4fc4-a29d-f56f3ea88103/original/woocommerce-gateway-placetopay-2_24_1-php-8_x.zip
- https://evertecinc.com/en/solution/placetopay/
- https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php
- https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php
- https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php
- https://github.com/placetopay/woocommerce-gateway-placetopay/blob/3.2.2/src/GatewayMethod.php
- https://github.com/placetopay/woocommerce-gateway-placetopay/releases/tag/3.2.2