CVE-2018-5316: Patsatech Sagepay Server Gateway For Woocommerce

Medium severity, CVSS 6.1. EPSS: 3.7% chance of exploitation in the next 30 days.

The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

Affected products

  • Patsatech Sagepay Server Gateway For Woocommerce: before 1.0.9 (fixed in 1.0.9)

Published 2018-01-09. Last modified 2026-06-17.