XSS vulnerabilities
Recently worldpay implemented anti-samy measures that effectively destroy part of the opensource zen cart shop (about 1000 small business use this module and gateway), they are attempting to implement PCI DSS but seem to have no understanding of it or the concepts involved. They explained the measures were to stop possible XSS breaches.
Unfortunately their website is already full of XSS vulnerabilities which were published here:
http://www.zen-cart.com/forum/showpost.php?p=776363&postcount=364
they also appear not to understand some basic concepts of how their own payment system works and a Proof of Concept was presented to them that demonstrated that no matter what measures they took, their website could be used for phishing if someone had already made a payment to their system, it is actually possible to take a payment for a item, then repeatedly present a screen saying the payment never cleared, in the worldpay colours on their own website and just loop around and around taking multiple payments until the "victim" gets board and stops handing over their credit card details.
Declaration of Interest.
I maintain the RBSWorldPay module for zen cart, discovered the vulnerabilities and showed the proof of concept for phishing. Although having maintained the module, they have never granted a request for a developer account, nor will talk to me, so other forum members with worldpay accounts have to talk to them on my behalf.