Description
Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Patch Update
AI Analysis

Impact

WordPress Simple Payment plugin, versions up to 2.5.4, contains a Cross Site Scripting flaw that allows attackers to inject malicious scripts into web pages because user‑supplied data is reflected without proper validation, permitting the injection of arbitrary JavaScript. The flaw can be exploited by embedding malicious scripts into plugin fields that are subsequently rendered in the user interface.

Affected Systems

The vulnerability affects the WordPress Simple Payment plugin developed by Ido Kobelkowsky, versions 2.5.4 and earlier. All installations of these vulnerable versions are at risk until the plugin is updated.

Risk and Exploitability

The EPSS score indicates a very low exploitation probability. The CVSS score of 6.5 is not listed in CISA KEV. Based on the description, the likely attack vector is client‑side injection; an attacker might target a site visitor by crafting a link or exploiting a form that the plugin processes. Successful exploitation would run malicious JavaScript in the victim's browser, enabling client‑side attacks. No hard prerequisites are required.

Generated by OpenCVE AI on September 21, 2026 at 04:31 UTC.

Remediation

Vendor Solution

Update the WordPress Simple Payment Plugin to the latest available version (at least 2.5.6).


OpenCVE Recommended Actions

  • Update the WordPress Simple Payment Plugin to at least version 2.5.6, which removes the XSS flaw.
  • If an update is not immediately possible, temporarily disable the Simple Payment plugin to prevent exploitation until a patch can be applied.
  • Review the plugin’s input fields and ensure that any custom code or extensions enforce proper escaping and validation to guard against future injection issues.

Generated by OpenCVE AI on September 21, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Ido Kobelkowsky
Ido Kobelkowsky simple Payment
Wordpress
Wordpress wordpress
Vendors & Products Ido Kobelkowsky
Ido Kobelkowsky simple Payment
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
Title WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ido Kobelkowsky Simple Payment
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T19:45:17.374Z

Reserved: 2026-07-13T06:15:10.221Z

Link: CVE-2026-62111

cve-icon Vulnrichment

Updated: 2026-09-11T19:45:13.961Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:43.987

Modified: 2026-09-11T21:17:02.457

Link: CVE-2026-62111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')