Known vulnerabilities in PayU India
CommercePro payment plugin by PayU Payment Gateway (India) for WooCommerce (tested from 5.3 to 9.8.1).
5Reported vulnerabilities
9.8Highest CVSS score
3.9.0Latest version
7,000+Active installs
What to do now
Update PayU India to 3.9.0 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-31022 | Critical | 0.7% | 3.8.7 and earlier | 3.8.8 |
June 5, 2025 |
| CVE-2024-12264 | Critical | 0.7% | 0 to 3.8.3 (inclusive) | 3.8.4 |
January 7, 2025 |
| CVE-2024-27193 | Medium | 0.4% | 3.8.8 and earlier | 3.8.9 |
February 26, 2024 |
| CVE-2026-13692 | Medium | 0.2% | 0 up to (but not including) 3.9.0 | 3.9.0 |
July 29, 2026 |
| CVE-2026-61954 | Medium | 0.3% | 3.8.9 and earlier | 3.9.0 |
July 22, 2026 |