Description
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Published: 2026-08-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to payment settings
Action: Immediate Patch
AI Analysis

Impact

The Simple Payment plugin for WordPress versions 2.5.2 or earlier contains an unauthenticated broken access control flaw that permits attackers to bypass authentication checks and access privileged functions or modify payment settings. This vulnerability allows unauthenticated users to potentially alter configuration values, view sensitive data, or manipulate transaction processing without authorization. No exploitation or confirmation of data disclosure is provided in the current description, but the lack of authentication checks creates a vector for privilege escalation within the plugin ecosystem.

Affected Systems

The vulnerability affects the WordPress Simple Payment plugin made by yalla ya! in versions up to and including 2.5.2. WordPress site administrators with this plugin installed and not updated to at least 2.5.3 are exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates high potential impact if exploited. The EPSS score is not available, so the likelihood of exploitation in the wild cannot be quantified from this data. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the exposed administrative endpoints over the web without credentials, so any user with access to the site can exploit the flaw. Until the plugin is updated, the risk is moderate to high for unsophisticated attackers.

Generated by OpenCVE AI on August 28, 2026 at 16:43 UTC.

Remediation

Vendor Solution

Update the WordPress Simple Payment Plugin to the latest available version (at least 2.5.3).


OpenCVE Recommended Actions

  • Update the WordPress Simple Payment plugin to version 2.5.3 or later.
  • If an immediate update is not possible, temporarily disable or deactivate the Simple Payment plugin until the patch is applied.
  • After applying the update, review and audit the plugin’s configuration settings to ensure no unauthorized changes were made.

Generated by OpenCVE AI on August 28, 2026 at 16:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yalla Ya!
Yalla Ya! simple Payment
Vendors & Products Wordpress
Wordpress wordpress
Yalla Ya!
Yalla Ya! simple Payment

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Title WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Wordpress Wordpress
Yalla Ya! Simple Payment
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-28T16:04:28.368Z

Reserved: 2026-08-27T12:24:18.942Z

Link: CVE-2026-81767

cve-icon Vulnrichment

Updated: 2026-08-28T16:04:14.151Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:30.590

Modified: 2026-08-28T20:20:13.023

Link: CVE-2026-81767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:31:51Z

Weaknesses