The latest version is WooCommerce Redsys Gateway 27.1.4, Released on December 1, 2025
Here’s what’s changed in WooCommerce Redsys Gateway Version 26.2.3
* UPDATE: Corrected automatic user login flow after account creation by replacing wp_set_current_user() and wp_set_auth_cookie() with wp_signon().
* UPDATE: Added username existence check to avoid conflicts when generating usernames from email addresses.
* UPDATE: Sanitized $_POST['apple-token-redsys'] input variable.
* UPDATE: Secured wp_remote_*() calls with host validation to prevent SSRF vulnerabilities.
* UPDATE: Added permission_callback checks for REST endpoints using referer validation to avoid public access.
* UPDATE: Enabled CURLOPT_SSL_VERIFYHOST = 2 and CURLOPT_SSL_VERIFYPEER = 1 in Redsys API library to enforce proper SSL certificate validation and prevent MITM attacks.
* UPDATE: Justified use of wp_redirect() for external OAuth flow with proper comment.
* UPDATE: Escaped dynamic CSS output for safe rendering.
View the full WooCommerce Redsys Gateway Changelog
Get WooCommerce Redsys Gateway Version 26.2.3 with 12 months of updates for just $25!
Already a WPspring Club Member?
WooCommerce Redsys Gateway Version 26.2.3 Released on July 10, 2025, is now available from your account downloads page. Sign up at wpspri.ng/club


