
Wava Payment Plugin Security & Risk Analysis
wordpress.org/plugins/wava-paymentAcepta pagos con Nequi, DaviPlata y Bre-B en WooCommerce. Conecta Stripe para ventas internacionales y gestiona tu tesorería con Wava.
Is Wava Payment Plugin Safe to Use in 2026?
Mostly Safe
Score 78/100Wava Payment Plugin is generally safe to use. 1 past CVE were resolved.
The "wava-payment" v0.3.7 plugin exhibits a concerning security posture due to a significant lack of authentication and authorization checks across its identified entry points. All three REST API routes lack permission callbacks, rendering them accessible to any user, including unauthenticated ones. This creates a substantial attack surface where these routes can be manipulated without proper validation. Furthermore, the analysis reveals that 100% of the plugin's output is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by these unprotected REST API routes could be maliciously crafted to execute arbitrary JavaScript in the user's browser.
Despite the concerning findings from the static analysis, the plugin has a clean vulnerability history with zero recorded CVEs. This suggests that either the plugin has not been a target for vulnerability discovery, or that its previous versions (prior to v0.3.7) did not contain exploitable flaws. However, the current static analysis results cannot be ignored. The absence of capability checks and nonce verification, coupled with the unprotected REST API endpoints and unescaped output, presents a clear and present danger. While the lack of dangerous functions and the use of prepared statements for SQL queries are positive indicators, they do not mitigate the severe risks posed by the other identified weaknesses. A cautious approach is recommended, prioritizing the remediation of these critical security flaws.
Key Concerns
- REST API routes lack permission callbacks
- Output escaping is not implemented
- No nonce checks on entry points
- No capability checks on entry points
Wava Payment Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wava Payment <= 0.3.7 - Missing Authorization
Wava Payment Plugin Release Timeline
Wava Payment Plugin Code Analysis
Output Escaping
Wava Payment Plugin Attack Surface
REST API Routes 3
WordPress Hooks 10
Maintenance & Trust
Wava Payment Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Wava Payment Plugin Alternatives
Recaudos para Nequi
recaudos-nequi
Accept Nequi payments in WooCommerce. Show your Nequi number to customers with step-by-step instructions to complete the transfer.
Transferencias para Bre-B
transferencias-breb
Accept Bre-B payments in WooCommerce. Show your Bre-B key to customers with step-by-step instructions to complete the transfer from any Colombian bank …
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 120+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Wava Payment Plugin Developer Profile
1 plugin · 100 total installs
How We Detect Wava Payment Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wava-payment/assets/css/admin.css/wp-content/plugins/wava-payment/assets/css/checkout.csswava-payment/assets/css/admin.css?ver=wava-payment/assets/css/checkout.css?ver=HTML / DOM Fingerprints
/wp-json/wava-payment/webhook/orders/wp-json/wava-payment/webhook/install