Yanco develops payment-gateway plugins for WooCommerce e-commerce platforms, with a documented exposure pattern centered on authorization weaknesses in its payment-processing integrations. The recurring signal across its product line reflects the sensitive nature of payment handling and the need for strict access controls in financial transaction flows; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yanco over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4947MEDIUM The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX act | Oct 20, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-4948MEDIUM The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_cvr_data AJAX act | Sep 14, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yanco.
Media articles that mention a CVE ID that affects a product developed by Yanco — matched by CVE ID, not by vendor name.