See how ecpay compares to other vendors in security performance
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clearecpaydebuglog' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.