Impact
The WP Easy Pay – Payment and Donation form Builder for Square plugin is affected by a missing authorization check that allows an attacker who is logged in with the subscriber role or higher to change the status of any post or page to draft via a specific AJAX action. The vulnerability represents a classic authorization bypass (CWE‑862). It does not directly expose confidential information but can unpublish arbitrary site content, disrupting site availability and potentially harming business operations.
Affected Systems
All WordPress sites running any version of the WP Easy Pay plugin up to and including 4.5.0, as distributed by the vendor saadiqbal, are affected. The flaw can be exploited by any authenticated user with subscriber role or higher, allowing them to modify the status of any post or page to draft via the wpep_draft_confirm AJAX action.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in the moderate range, and the EPSS score of less than 1% indicates that, at the time of assessment, the likelihood of exploitation is low. The vulnerable AJAX endpoint requires a valid authenticated session with at least subscriber privileges and must be explicitly triggered. Because the attacker must be a legitimate logged‑in user, the attack surface is limited. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment