CVE-2026-103346: WordPress Payflex Payment Gateway plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Payflex Payment Gateway pluginto a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires no privileges, and has low attack complexity. It does require user interaction, meaning an attacker would need to induce a user to access or interact with crafted content.
Are standard installations affected?
The provided data identifies affected versions through 2.7.1, but does not state whether exploitation depends on a non-default configuration. Treat installations running version 2.7.1 or an earlier affected version as potentially exposed.
What is the likely impact if exploitation succeeds?
The vulnerability is reflected XSS with low impacts to confidentiality, integrity, and availability. The CVSS vector also indicates scope can change, so effects may extend beyond the vulnerable component's original security authority.