Medium 5.3
2026-05-06< 8.7.12
CVE-2026-3208
Minimum safe version
8.7.12
Update to 8.7.12 or later to address 5 fixable vulnerabilities
CVE-2026-3208
WordPress Mercado Pago payments for WooCommerce Plugin 7.3.0 - 7.6.1 is vulnerable to Arbitrary File Download
CVE-2022-45068
WordPress Mercado Pago payments for WooCommerce Plugin <= 6.6.0 is vulnerable to Cross Site Request Forgery (CSRF)
Mercado Pago payments for WooCommerce <= 6.6.0 - Cross-Site Request Forgery