Payment Gateway Authorize.Net CIM for WooCommerce Security & Risk Analysis

wordpress.org/plugins/authnet-cim-for-woo

Authorize.Net CIM for WooCommerce allows merchants to accept credit cards with support for stored cardholder profiles, subscriptions, and pre-orders.

1K active installs v2.1.2 PHP + WP 4.0+ Updated Sep 24, 2023
authorize-netauthorize-net-cimcustomer-information-managerwoocommercewoocommerce-authorize-net
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 30, 2025
Safety Verdict

Is Payment Gateway Authorize.Net CIM for WooCommerce Safe to Use in 2026?

Use With Caution

Score 63/100

Payment Gateway Authorize.Net CIM for WooCommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 30, 2025Updated 2yr ago
Risk Assessment

The authnet-cim-for-woo plugin v2.1.2 exhibits a mixed security posture. On the positive side, the static analysis shows excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. The plugin also correctly implements nonce checks for its two AJAX entry points and has no identified file operations or raw SQL queries. The absence of dangerous functions and taint analysis revealing no unsanitized paths further contribute to its good internal code quality.

However, the plugin's vulnerability history presents a significant concern. There is one known medium-severity CVE that remains unpatched. The common vulnerability type being 'Missing Authorization' in past issues suggests a recurring pattern that attackers could exploit. While current code analysis shows no immediate authorization flaws on entry points, the historical trend and the presence of an unpatched vulnerability are critical indicators of potential risk. The plugin also makes external HTTP requests, which could be a vector if not handled securely, although this is not explicitly flagged as a vulnerability in the static analysis.

In conclusion, authnet-cim-for-woo v2.1.2 benefits from strong internal coding practices, but the presence of an unpatched medium-severity CVE and a history of authorization issues significantly elevate its risk profile. Users should prioritize addressing the unpatched vulnerability to mitigate the most pressing security threat.

Key Concerns

  • Unpatched CVE (medium severity)
  • Vulnerability history of missing authorization
Vulnerabilities
1

Payment Gateway Authorize.Net CIM for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68013medium · 4.3Missing Authorization

Payment Gateway Authorize.Net CIM for WooCommerce <= 2.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Deletion

Dec 30, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway Authorize.Net CIM for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
93 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped93 total outputs
Attack Surface

Payment Gateway Authorize.Net CIM for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_delete_cardincludes\legacy\class-wc-cardpay-authnet-credit-cards.php:22
authwp_ajax_add_update_cardincludes\legacy\class-wc-cardpay-authnet-credit-cards.php:23
WordPress Hooks 17
actionwcs_resubscribe_order_createdincludes\class-wc-cardpay-authnet-gateway-addons.php:36
filterwoocommerce_subscription_payment_metaincludes\class-wc-cardpay-authnet-gateway-addons.php:39
filterwoocommerce_subscription_validate_payment_metaincludes\class-wc-cardpay-authnet-gateway-addons.php:40
actionadmin_noticesincludes\class-wc-cardpay-authnet-gateway.php:70
actionwoocommerce_after_my_accountincludes\legacy\class-wc-cardpay-authnet-credit-cards.php:20
actionwp_enqueue_scriptsincludes\legacy\class-wc-cardpay-authnet-credit-cards.php:21
actionwcs_resubscribe_order_createdincludes\legacy\class-wc-cardpay-authnet-gateway-addons.php:29
filterwoocommerce_subscription_payment_metaincludes\legacy\class-wc-cardpay-authnet-gateway-addons.php:32
filterwoocommerce_subscription_validate_payment_metaincludes\legacy\class-wc-cardpay-authnet-gateway-addons.php:33
actionadmin_noticesincludes\legacy\class-wc-cardpay-authnet-gateway.php:68
actionplugins_loadedwoocommerce-cardpay-authnet.php:88
actionwoocommerce_order_status_completedwoocommerce-cardpay-authnet.php:89
actioninitwoocommerce-cardpay-authnet.php:90
actionwp_enqueue_scriptswoocommerce-cardpay-authnet.php:91
actionbefore_woocommerce_initwoocommerce-cardpay-authnet.php:92
filterwoocommerce_payment_gatewayswoocommerce-cardpay-authnet.php:142
filterwoocommerce_get_customer_payment_tokenswoocommerce-cardpay-authnet.php:143
Maintenance & Trust

Payment Gateway Authorize.Net CIM for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 24, 2023
PHP min version
Downloads59K

Community Trust

Rating84/100
Number of ratings5
Active installs1K
Developer Profile

Payment Gateway Authorize.Net CIM for WooCommerce Developer Profile

cardpaysolutions

4 plugins · 1K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway Authorize.Net CIM for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/authnet-cim-for-woo/assets/css/authnet-admin.css/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-admin.js/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-checkout.js
Script Paths
/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-admin.js/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-checkout.js
Version Parameters
authnet-cim-for-woo/assets/css/authnet-admin.css?ver=authnet-cim-for-woo/assets/js/authnet-admin.js?ver=authnet-cim-for-woo/assets/js/authnet-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc_cardpay_authnet_gateway_wrap
HTML Comments
Copyright 2016 Cardpay Solutions, Inc. (email : sales@cardpaysolutions.com)This program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General License+3 more
Data Attributes
data-authnet-customer-iddata-authnet-payment-iddata-authnet-token
JS Globals
WC_Cardpay_Authnet_Checkout
FAQ

Frequently Asked Questions about Payment Gateway Authorize.Net CIM for WooCommerce