Known vulnerabilities in PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)
Connect and manage all your payment methods, offer shoppers a beautiful Express Checkout, and reduce cart abandonment.
5Reported vulnerabilities
6.5Highest CVSS score
1.120.57Latest version
300+Active installs
What to do now
Update PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) to 1.120.47 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-9463 | Medium | 0.3% | 0 to 1.117.5 (inclusive) | 1.117.6 |
September 10, 2025 |
| CVE-2024-11362 | Medium | 0.4% | 0 to 1.112.0 (inclusive) | 1.113.0 |
November 23, 2024 |
| CVE-2025-14978 | Medium | 0.2% | 0 to 1.119.8 (inclusive) | 1.119.9 |
January 20, 2026 |
| CVE-2025-58634 | Medium | 0.2% | 1.117.4 and earlier | 1.117.5 |
September 3, 2025 |
| CVE-2026-9618 | Medium | 0.1% | 0 to 1.120.46 (inclusive) | 1.120.47 |
May 28, 2026 |