Description
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated SQL Injection exists in the WordPress Epayco plugin up to version 8.4.6, allowing an attacker to craft arbitrary SQL statements. The flaw can compromise data confidentiality, integrity, and availability by modifying or extracting sensitive database contents. This category of vulnerability falls under CWE-89.

Affected Systems

The issue affects the ePayco WordPress plugin supplied by the ePayco vendor, specifically all releases through 8.4.6. Systems running WordPress and any site that has installed the Epayco plugin without updating beyond 8.4.6 are at risk.

Risk and Exploitability

With a CVSS score of 9.3, this vulnerability is considered critical. No EPSS data is available. Based on the description, the flaw is unauthenticated, allowing any actor to send malicious queries. The exact entry point is not specified in the provided data; it is likely an exposed plugin endpoint. The vulnerability is not listed in the CISA KEV catalog, yet its high severity and ease of exploitation present a significant threat.

Generated by OpenCVE AI on August 27, 2026 at 11:20 UTC.

Remediation

Vendor Solution

Update the WordPress Epayco Plugin to the latest available version (at least 8.4.7).


OpenCVE Recommended Actions

  • Update the WordPress Epayco Plugin to the latest version (at least 8.4.7).
  • Remove or disable the plugin if it is no longer required.
  • Conduct a review of all other WordPress plugins for known vulnerabilities and ensure they are patched to the latest secure releases.

Generated by OpenCVE AI on August 27, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Title WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-27T08:59:55.061Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:36.880

Modified: 2026-08-27T10:16:36.880

Link: CVE-2026-78260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T11:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')