WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Razorpay for WooCommerce

Start accepting payments in minutes with 100% digital onboarding & feature filled Razorpay payment gateway with the WooCommerce plugin.

4Reported vulnerabilities
5.3Highest CVSS score
4.8.7Latest version
100,000+Active installs

What to do now

Update Razorpay for WooCommerce to 4.7.9 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 15, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-14294 Medium 5.3 0.4% 0 to 4.7.8 (inclusive) 4.7.9 February 19, 2026
CVE-2026-39656 Medium 5.3 0.2% 4.8.3 and earlier 4.8.4 February 16, 2026
WF-e6a2b2f6-c648-4755-be24-92c7f287813e Medium 4.3 4.5.6 and earlier 4.5.7 November 28, 2023
WF-f59cf3d6-06a0-42ec-a604-5f59c6b2be40 Medium 4.3 4.5.6 and earlier 4.5.7 November 28, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.