#Paygent
CVE-2025-14078 - PAYGENT for WooCommerce
CVE ID : CVE-2025-14078

Published : Jan. 17, 2026, 8:24 a.m. | 55 minutes ago

Description : The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This ...
CVE-2025-14078 - PAYGENT for WooCommerce <= 2.4.6 - Missing Authorization to Unauthenticated Payment Callback Manipulation
The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on the paygent_check_webhook function combined with the paygent_permission_callback function unconditionally returning true on line 199. This makes it possible for unauthenticated attackers to …
cvefeed.io
January 17, 2026 at 10:28 AM
YTGATE and Paygent Team Up to Enhance E-Commerce Payment Optimization Services#Japan#Tokyo#YTGATE#YTGuard#Paygent
YTGATE and Paygent Team Up to Enhance E-Commerce Payment Optimization Services
YTGATE collaborates with Paygent to launch YTGuard, an innovative payment optimization service for e-commerce businesses, enhancing user experience.
third-news.com
June 30, 2026 at 1:45 AM
Valuence Japan Expands Auction Pay Payment Service to Penguin Trade#Japan#Tokyo#Valuence_Japan#Auction_Pay#Penguin_Trade
Valuence Japan Expands Auction Pay Payment Service to Penguin Trade
Valuence Japan collaborates with Paygent and Infcurion to launch Auction Pay at Penguin Trade, enhancing BtoB auction payment solutions.
third-news.com
May 12, 2026 at 2:09 AM
Valuence Japan Launches New Auction Payment Service to Enhance B2B Transactions#Japan#Tokyo#Valuence_Japan#Auction_Pay#Paygent
Valuence Japan Launches New Auction Payment Service to Enhance B2B Transactions
Valuence Japan has partnered with Paygent and Infcurion to introduce Auction Pay, improving cash flow and efficiency in B2B auctions.
third-news.com
October 28, 2025 at 1:56 AM
PAYGENT for WooCommerce <= 2.4.6 - Missing Authorization to Unauthenticated P... The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an...

Origin | Interest | Match
CVE-2025-14078 | THREATINT
CVE-2025-14078: The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on the paygent_check_webhook function combined with the paygent_permission_callback ...
cve.threatint.eu
January 18, 2026 at 8:49 AM