
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Security & Risk Analysis
wordpress.org/plugins/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hangTích hợp thanh toán quét mã QR Code MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Is Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Safe to Use in 2026?
Mostly Safe
Score 74/100Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The plugin 'bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang' v2.0.1 presents a significant security risk due to a combination of unprotected entry points and a history of high-severity vulnerabilities. While the plugin utilizes prepared statements for SQL queries and has some output escaping, the lack of authentication checks on all AJAX handlers and the REST API route is a major concern, creating a large attack surface. The presence of two known high-severity vulnerabilities, with one currently unpatched, specifically related to Cross-Site Scripting (XSS), indicates a pattern of insecure input handling.
The static analysis reveals that all 7 identified entry points are unprotected, meaning an attacker could potentially trigger malicious actions without proper user authentication or authorization. The two flows with unsanitized paths in the taint analysis further support the potential for XSS or other injection vulnerabilities, even though they are not classified as critical or high in this specific scan. The bundled TCPDF library is also a potential concern if it's an outdated version, although this specific data doesn't confirm its version or known vulnerabilities.
In conclusion, the plugin's security posture is weak. The high number of unprotected entry points and the existing unpatched high-severity XSS vulnerability are critical indicators of risk. While good practices like prepared statements are present, they are overshadowed by the fundamental security flaws in access control and input sanitization. Users should be extremely cautious when deploying this plugin, and immediate remediation of the unpatched CVE is paramount.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- Unpatched high severity CVE
- Unsanitized paths in taint analysis
- Low output escaping percentage
- Bundled TCPDF library (potential outdated version)
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam <= 2.0.0 - Cross-Site Scripting
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 17
Maintenance & Trust
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Maintenance & Trust
Maintenance Signals
Community Trust
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Alternatives
Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng
casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang
Kết nối các ngân hàng Việt Nam vào Woocommerce, tự động xác nhận đơn hàng đã thanh toán. Hỗ trợ hơn 10 ngân hàng : VietinBank, OCB, Vietcombank, Techc …
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank
qh-testpay
Tích hợp thanh toán quét mã QR Code với MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV
thanh-toan-chuyen-khoan
Tích hợp thanh toán quét mã QR Code với MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Developer Profile
1 plugin · 500 total installs
How We Detect Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/css/style.css/wp-content/plugins/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/js/easy.qrcode.js/wp-content/plugins/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/js/js.jsassets/js/easy.qrcode.jsassets/js/js.js/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/css/style.css?ver=/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/js/easy.qrcode.js?ver=/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/js/js.js?ver=HTML / DOM Fingerprints
mpay-payment-gateway<!-- Generated by haibasoft.com -->data-noncedata-gatewaydata-actionmpay_ajax_object/wp-json/mpay/v1/payment-status/wp-json/mpay/v1/sync-order