PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

From April 13 SC Magazine UK (Revised from their earlier April 11 story): Worldpay’s Gateway

By Raymond Pucci
April 15, 2016
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

We recently commented on an April 11, 2016 article in SC Magazine UK which stated that Worldpay’s electronic payment gateway setup pages had potential operational vulnerabilities on credit card details, according to a security researcher. SC Magazine UK updated the story on April 13 to add that the vulnerability was reported on January 27, 2015, and successfully patched by Worldpay within 48 hours. A second flaw was reported in April, 2015, and successfully patched the next day.

Worldpay confirms that there has been no data breach and customer data on Worldpay’s payment processing systems remain secure. The SC Magazine UK revisions are as follows, and the complete revised article is available on the link below:

Technology industry watchers have castigated payments processing service Worldpay for potential operational vulnerabilities. Worldpay is billed as a secure payment gateway for businesses that incorporates the worlds of online payments, card machines and telephone payments.

The firm itself proposes that it delivers a secure proprietary technology platform to enable ‘merchants’ to accept a vast array of payment types, across multiple channels, anywhere in the world.

It is precisely the Worldpay Merchant Portal that Randy Westergren has a problem with. As a senior software developer at XDA Developers, Westergren claims he has found “multiple vulnerabilities” in the Worldpay Merchant Portal. He further states that this is not the first time he has uncovered compliance issues with this kind of payment gateway technology.

“One, an attacker can designate his own postback URL, meaning that after a transaction occurs on the merchant’s site, Worldpay’s server would post the results/details of that transaction to the attacker’s server, including the customer’s name, billing address, phone numbers, email addresses and raw information of the transaction,” he said, referring to a flaw that he reported to Worldpay last year. He reported the problem on 27 January 2015 and it was patched within 48 hours, he says.

“The other danger is that the attacker can control the form’s HTML, meaning it could be used to attack the user client-side (e.g. XSS, clickjacking, phishing),” he said. This flaw was reported in April 2015 and patched the next day.

Overview by Raymond Pucci, Associate Director, Research Services at Mercator Advisory Group

Read the full story here

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    gift card strategy

    The Gift Card Shift: From Convenience to Core Shopping Strategy

    February 18, 2026
    Tina Shirley

    From Cross-Border Payments to Community Banks: The Future of Zelle®

    February 17, 2026
    Startups: Fintechs Data Streaming Technology in Banking, corporates Enriched Data vs Faster Payments

    Fighting Fraud in the Era of Faster Payments

    February 13, 2026
    cross-border payments

    Solving for Fraud in Cross-Border Payments Requires Better Counterparty Verification

    February 12, 2026
    agentic commerce

    Demystifying the Agentic Commerce Enigma

    February 11, 2026
    payment gateways

    How Payment Gateways for Businesses Can Help You Offer Your Customers More Options

    February 10, 2026
    Reserve Bank of India (RBI) Extends Mandate for Tokenization to June '22

    Late Payments? Governments Are Taking Action

    February 9, 2026
    ai phishing

    The Fraud Epidemic Is Testing the Limits of Cybersecurity

    February 6, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result