PatchSiren

gopayplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM gopayplugins CVE published 2026-09-19

CVE-2026-75959

The GoPay for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.