CVE-2026-11324 Details
Description
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
A reflected cross-site scripting vulnerability has been identified in the WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress, affecting versions through 3.2.2. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'redirect-url' parameter. These scripts could be executed if a user is tricked into clicking a link.
No known patch is available. It is recommended to uninstall the affected plugin and find a replacement.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WooCommerce Placetopay Gateway | <= 3.2.2 (semver) |
CPE
Remediation
| |
| WooCommerce Placetopay Gateway Belice | <= 3.2.2 (semver) |
CPE
Remediation
| |
| WooCommerce Placetopay Gateway Colombia | <= 3.2.2 (semver) |
CPE
Remediation
| |
| WooCommerce Placetopay Gateway Ecuador | <= 3.2.2 (semver) |
CPE
Remediation
| |
| WooCommerce Placetopay Gateway Honduras | <= 3.2.2 (semver) |
CPE
Remediation
| |
| WooCommerce Placetopay Gateway Uruguay | <= 3.2.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | [email protected] |
Volerion