← WordPress Vulnerabilities
WordPress security by component

flow-payment

flow-payment is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 18, 2026; the highest CVE/CNA score is 5.1.

Plugin slug: flow-payment

CVE-2026-57857: Flow Payment cancellation messages can execute script in checkout

Flow Payment 3.0.8 and earlier reflects its cancellation error_message into the WooCommerce checkout notice without safely escaping it. An attacker can place script in a crafted cancellation link; if a shopper with an active checkout follows that link, the script runs as part of the store. This is a reflected XSS issue rather than a server takeover, but it can still be used to alter checkout content or steal browser-accessible data.

PublishedJul 18, 2026
Known safe version3.0.9
Safe version
Jul 18, 2026 CVE-2026-57857
Flow Payment cancellation messages can execute script in checkout
Flow Payment 3.0.8 and earlier reflects its cancellation error_message into the WooCommerce checkout notice without safely escaping it. An attacker can place script in a crafted cancellation link; if a shopper with an active checkout follows that link, the script runs as part of the store. This is a reflected XSS issue rather than a server takeover, but it can still be used to alter checkout content or steal browser-accessible data.
3.0.9
CVE5.1
NVDPending