Executive brief
The IDPay Payment Gateway plugin for WooCommerce, which facilitates online payments for WordPress stores, contains a security flaw that exposes sensitive information. An unauthorized person could access private data that should be protected, potentially leading to further attacks or the compromise of customer and system details. As of the latest report, there is no official patch available to fix this issue.
Technical details
The IDPay Payment Gateway for Woocommerce plugin (versions <= 2.2.5) is vulnerable to an unauthenticated sensitive data exposure flaw, classified as CWE-497. The vulnerability allows a remote attacker to access sensitive system or transaction information without requiring any authentication or user interaction. This exposure occurs due to insufficient access controls within the plugin's components. At the time of the advisory, no official patch has been released by the developer, and users are advised to monitor for updates or seek alternative mitigations.
Affected products
- IDPay IDPay Payment Gateway for Woocommerce <= 2.2.5
Timeline
- 2026-03-05: other: Vulnerability reported by researcher Chawabhon Netisingha (JNX03)
- 2026-04-06: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: CVE published to NVD