Executive brief
The Custom Payment Gateways for WooCommerce plugin for WordPress, which allows businesses to create specialized payment options for their online stores, contains a security flaw. An unauthenticated attacker can inject malicious scripts into the website by submitting a specially crafted checkout request. If successful, these scripts will execute in the browsers of other users who visit the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Custom Payment Gateways for WooCommerce plugin for WordPress due to insufficient input sanitization and output escaping of the 'alg_wc_cpg_input_fields' parameter. The flaw is located within the class-alg-wc-custom-payment-gateways-input-fields.php component. An unauthenticated attacker can exploit this by submitting a crafted POST request during the checkout process. Notably, the vulnerability can be triggered even if no custom input fields have been configured in the plugin settings. Successful exploitation allows the injection of arbitrary web scripts that execute in the context of a user's session when they view the affected page. The issue is present in all versions up to and including 2.1.0.
Affected products
- dhruvin Custom Payment Gateways for WooCommerce up to, and including, 2.1.0
Timeline
- 2026-07-01: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/tags/2.1.0/includes/class-alg-wc-custom-payment-gateways-input-fields.php
- https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/tags/2.1.0/includes/class-alg-wc-custom-payment-gateways-input-fields.php
- https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/tags/2.1.0/includes/class-alg-wc-custom-payment-gateways-input-fields.php
- https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/trunk/includes/class-alg-wc-custom-payment-gateways-input-fields.php
- https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/trunk/includes/class-alg-wc-custom-payment-gateways-input-fields.php
- https://plugins.trac.wordpress.org/browser/custom-payment-gateways-woocommerce/trunk/includes/class-alg-wc-custom-payment-gateways-input-fields.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3578163%40custom-payment-gateways-woocommerce&new=3578163%40custom-payment-gateways-woocommerce&sfp_email=&sfph_mail=