Executive brief
Commerce Elavon is a Drupal module that integrates payment processing for the Elavon Virtual Merchant gateway, handling credit card transactions and payment authorization. The maintainers have ceased development and failed to fix a critical security vulnerability, rendering the module unsupported and potentially exposing sites to compromise. Any Drupal site running this module is advised to uninstall it immediately or seek alternative payment solutions.
Technical details
The exact technical nature of the vulnerability is not disclosed in the advisory, but the Drupal security team has marked the Commerce Elavon module as unsupported and critical due to a known security issue that remains unpatched. The module handles sensitive payment card processing and authorization workflows, making any unpatched vulnerability in this context high-risk. No patch is available, and the maintainer has abandoned the project. The attack vector and specific exploitation path are not detailed, but the criticality rating suggests remote exploitation may be possible. Sites must either uninstall the module, seek alternative maintained payment solutions, or hire external developers to fix the vulnerability.
Affected products
- Drupal Commerce Elavon all versions
Timeline
- 2026-07-22: disclosed: Marked unsupported by Drupal security team
- 2026-08-25: advisory: NVD entry published