
CVE-2026-6939 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and… https://www.cve.org/CVERecord?id=CVE-2026-6939
Post summary
The CorvusPay WooCommerce Payment Gateway plugin suffers from a stored XSS flaw in the 'approval_code' parameter across all versions up to the referenced CVE.
