
ABA PayWay Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/aba-payway-woocommerce-payment-gatewayPayWay is Cambodia's leading online payment gateway provided by Advanced Bank of Asia Ltd. (ABA Bank). It offers multiple way of checkout options …
Is ABA PayWay Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100ABA PayWay Payment Gateway for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "aba-payway-woocommerce-payment-gateway" v2.1.8 plugin exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and having no reported critical or high-severity vulnerabilities in its history, significant concerns exist regarding its attack surface and output sanitization. The presence of two AJAX handlers without authentication checks represents a substantial risk, as these entry points are readily exploitable by unauthenticated users. Furthermore, only 26% of output is properly escaped, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, a pattern corroborated by its vulnerability history which lists XSS as a common type.
The static analysis indicates a lack of critical taint flows or dangerous functions, which is positive. However, the absence of nonce checks and capability checks on the unprotected AJAX endpoints exacerbates the risk of unauthorized actions or data manipulation. The single external HTTP request is not inherently a problem without further context, but it's an area to monitor. The plugin's vulnerability history, with a past medium vulnerability and a common XSS pattern, combined with the current low escape rate for output, points to a recurring weakness in input validation and output sanitization. The fact that the last vulnerability was recent (though in the future, likely a data entry error) and that it's unpatched suggests a potential ongoing security concern if not addressed proactively.
In conclusion, while the plugin avoids some common pitfalls like raw SQL queries, its unprotected AJAX handlers and poor output escaping create a considerable security risk. The historical pattern of XSS vulnerabilities further emphasizes the need for diligent code review and patching. Users should be cautious, and developers should prioritize addressing the unauthenticated entry points and improving output sanitization to mitigate XSS risks.
Key Concerns
- Unprotected AJAX handlers (2)
- Low output escaping percentage (26%)
- Missing nonce checks on AJAX
- Missing capability checks
- Medium vulnerability in history (past)
ABA PayWay Payment Gateway for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ABA PayWay Payment Gateway for WooCommerce <= 2.1.4 - Reflected Cross-Site Scripting
ABA PayWay Payment Gateway for WooCommerce Code Analysis
Output Escaping
ABA PayWay Payment Gateway for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
ABA PayWay Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ABA PayWay Payment Gateway for WooCommerce Alternatives
Live eftpos for WooCommerce
live-eftpos-for-woocommerce
The Live eftpos for WooCommerce plugin is the easy way to manage card payments via your online store.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
ABA PayWay Payment Gateway for WooCommerce Developer Profile
1 plugin · 200 total installs
How We Detect ABA PayWay Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aba-payway-woocommerce-payment-gateway/js/checkout.js/wp-content/plugins/aba-payway-woocommerce-payment-gateway/js/custom.jshttps://pay.payway.com.kh/v1/payplus/checkout.js?hide_close=aba-payway-woocommerce-payment-gateway/js/checkout.js?ver=aba-payway-woocommerce-payment-gateway/js/custom.js?ver=HTML / DOM Fingerprints
aba-modalaba-modal-contentid="aba_main_modal"id="aba_merchant_request"name="aba_merchant_request"id="req_time"id="merchant_id"id="api_version"+16 morewindow.aba_PAYWAY_AIM