mediumCVE-2026-11324

WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Browse WordPress security risks
ProductWooCommerce Placetopay Gateway Belice
CVSS6.1
EPSSNot scored yet
UpdatedJuly 19, 2026

Quick answer

WooCommerce Placetopay Gateway Belice should be reviewed and updated if it matches the affected versions. The recommended fix is to apply the vendor-supported patched version or the mitigation steps below, then retest the public website with Fixnx.

Who is affected

Affected versions

  • up to and including 3.2.2

Fixed versions

  • Apply the latest vendor-supported patched version.

How to fix it

WooCommerce Placetopay Gateway Belice is affected by CVE-2026-11324, an unauthenticated reflected cross-site scripting flaw in redirect-url. An attacker can build a malicious link that runs script in the browser of a user who opens it. No fixed version is listed in the imported Wordfence record; move to a vendor-supported patched release only after the linked advisory confirms the fix. Prioritize exposed production systems and accounts that can reach the affected feature.

  1. Inventory every WooCommerce Placetopay Gateway Belice deployment, version, exposed endpoint, environment, and owner.
  2. Confirm the installed release is not an affected version up to and including 3.2.2.
  3. No fixed version is listed in the imported Wordfence record; move to a vendor-supported patched release only after the linked advisory confirms the fix.
  4. Deactivate and replace the gateway until a fix is confirmed; if it must stay online, allowlist redirect destinations and block active content in redirect-url at the edge.
  5. Review relevant logs and look for encoded scripts or event handlers in redirect-url, related phishing links, and unusual order or account changes.
  6. Revoke the sessions of users who opened a malicious link and review their accounts and orders for unauthorized actions.
  7. Clear WordPress, object, page, CDN, and browser caches, then update the asset inventory and close any temporary controls only after validation.

Scan now. Google sign-in is only needed to unlock fix guidance.

Verify the fix

  • Confirm WooCommerce Placetopay Gateway Belice is on the patched version or mitigation stated above and record the exact deployed version.
  • Confirm redirect-url accepts only approved destinations and cannot place active content into the response.
  • Confirm the affected WordPress REST, AJAX, form, shortcode, upload, export, or admin feature is available only to the roles and requests that need it.
  • Review logs after remediation for continued exploit attempts or signs that the issue was used before the fix.
  • Rerun the relevant dependency, platform, vendor, or Fixnx security check and document the result, affected assets, change record, and cleanup evidence for CVE-2026-11324.

Related categories

Related security risks

More published guidance from the same primary category.

Trusted references

FAQ

What is affected by CVE-2026-11324?

WooCommerce Placetopay Gateway Belice versions listed as affected should be reviewed: up to and including 3.2.2.

What should I fix first?

Start with internet-facing sites, admin panels, login flows, plugins, themes, modules, packages, and systems that process user-controlled input or sensitive data.

How do I confirm the fix worked?

Apply the patched version or mitigation, clear caches where relevant, retest the affected workflow, and run a new Fixnx scan to verify public website exposure signals.

How are Fixnx security risk categories chosen?

Fixnx keeps one canonical risk page and assigns only broad, relevant categories such as ecosystem, technology area, or vulnerability class.