Description
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary posts, pages, and custom post types (bypassing the trash via force deletion) or change any published post to draft status.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorized content deletion
Action: Apply patch
AI Analysis

Impact

The WP Easy Pay plugin for WordPress suffers from an authorization bypass that allows any authenticated user with a Subscriber role or higher to permanently delete arbitrary posts, pages, and custom post types, or change any published content to draft status. Because the plugin does not correctly verify user permissions before executing these actions, a malicious actor can destroy content or disrupt a site’s public-facing pages. The flaw is a classic instance of CWE‑862, causing loss of data integrity and availability rather than confidentiality compromise.

Affected Systems

WordPress sites running the WP Easy Pay – Payment and Donation Form Builder for Square plugin, any version up to and including 4.5.0, are vulnerable. The affected code exists in the core plugin file, and the issue applies to all installations that have kept the plugin on the default subscriber role.

Risk and Exploitability

The CVSS v3.1 score of 4.3 categorizes this as a moderate severity vulnerability. The EPSS score of <1% indicates a very low exploitation likelihood under current threat intelligence. The flaw is not listed in the CISA KEV catalog, further suggesting limited public exploitation. However, because the attack vector requires only an authenticated session with subscription-level access, any user able to access the WordPress admin area can exploit the bug, which makes the requirement minimal from the attacker’s perspective.

Generated by OpenCVE AI on September 19, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Easy Pay to the latest version or any release past 4.5.0, where the authorization check has been implemented
  • Revoke or remove the ability to delete or modify posts from the Subscriber role and any other custom roles that may use WP Easy Pay capabilities
  • If a patch is not immediately available, disable the WP Easy Pay plugin or restrict its visibility and permission checks through a security plugin to block deletion operations until remediation

Generated by OpenCVE AI on September 19, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Saadiqbal
Saadiqbal wp Easy Pay – Payment And Donation Form Builder For Square
Wordpress
Wordpress wordpress
Vendors & Products Saadiqbal
Saadiqbal wp Easy Pay – Payment And Donation Form Builder For Square
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary posts, pages, and custom post types (bypassing the trash via force deletion) or change any published post to draft status.
Title WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Saadiqbal Wp Easy Pay – Payment And Donation Form Builder For Square
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:51.563Z

Reserved: 2026-06-19T16:38:41.210Z

Link: CVE-2026-12739

cve-icon Vulnrichment

Updated: 2026-09-19T14:13:28.967Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:58.937

Modified: 2026-09-19T15:16:57.997

Link: CVE-2026-12739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:30:07Z

Weaknesses