CVE-2018-5316: Patsatech Sagepay Server Gateway For Woocommerce
Medium severity, CVSS 6.1. EPSS: 3.7% chance of exploitation in the next 30 days.
The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.
Affected products
- Patsatech Sagepay Server Gateway For Woocommerce: before 1.0.9 (fixed in 1.0.9)
Published 2018-01-09. Last modified 2026-06-17.