Confidence
Medium. Based on ~30 public sources; independent user reviews sparse, security coverage substantial.
Pricing
Not disclosed
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Sources & method
Analyzed 9/30/2026 - 10 sources - Multiple CVEs in 2025–2026 (missing authorization, auth bypass, CSRF); patch immediately if installed.
official x3review x2security x3news x2
- CVE-2025-58634 — Missing Authorization, Missing authorization vulnerability in the PeachPay plugin.
- CVE-2025-14978 — Authentication bypass, Auth bypass flaw affecting PeachPay for WooCommerce.
- CVE-2026-9618 — CSRF to Stripe unlink, Cross-site request forgery (PeachPay <= 1.120.46) could unlink Stripe; rated Medium.
- Authenticated SQL injection report, Security researcher urged immediate updates for an authenticated SQL injection vulnerability in PeachPay Payments.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.