Description
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
Published: 2026-09-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated bypass within the WP EasyPay plugin allows an attacker to gain restricted access without credentials, potentially enabling manipulation of payment settings or transaction data. The vulnerability enables privilege escalation within the plugin’s protected functions, as indicated by CWE-472. This could compromise the integrity of payment workflows on a WordPress site.

Affected Systems

WordPress sites running the WP EasyPay plugin by Saad Iqbal, versions 4.5.3 and below, are affected. Only these versions are vulnerable; newer releases such as 4.5.4 contain the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating a moderate severity. EPSS data is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be via the web, as the bypass can be triggered without authentication if the vulnerable plugin is exposed to the public. Given the moderate score, the likelihood of exploitation remains uncertain but should still be mitigated promptly.

Generated by OpenCVE AI on September 3, 2026 at 17:25 UTC.

Remediation

Vendor Solution

Update the WordPress WP EasyPay Plugin to the latest available version (at least 4.5.4).


OpenCVE Recommended Actions

  • Upgrade the WordPress WP EasyPay plugin to version 4.5.4 or later.
  • Disable any custom payment gateway features that rely on the vulnerable plugin until the update is applied.
  • Deploy a Web Application Firewall rule that blocks suspicious requests targeting the WP EasyPay plugin’s administrative endpoints as a temporary safeguard.

Generated by OpenCVE AI on September 3, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
Title WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T17:41:42.653Z

Reserved: 2026-09-02T09:57:42.761Z

Link: CVE-2026-84762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:27.320

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:30:07Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter