Description
The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Disclosure and Deletion of Payment Parameters
Action: Immediate Patch
AI Analysis

Impact

The Autopay WordPress plugin before version 5.0.1 does not verify the signature on a payment callback, allowing attackers to trigger the callback without authentication. This flaw lets unauthenticated users retrieve or delete the payment parameters stored for other customers' orders, compromising confidentiality and integrity of sensitive payment data. The weakness is a typical authorization bypass identified as CWE-863.

Affected Systems

WordPress sites running the Autopay plugin, any version older than 5.0.1. The vulnerability targets browsers or services that can make requests to the plugin's payment callback endpoint.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit it by sending crafted HTTP requests to the callback URL, potentially creating or deleting payment parameters without needing valid credentials.

Generated by OpenCVE AI on September 18, 2026 at 04:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Autopay plugin to version 5.0.1 or newer, which enforces signature verification on payment callbacks.
  • If an update cannot be performed immediately, disable the Autopay plugin or block access to its payment callback endpoint until the patch is applied.
  • For a temporary mitigation, restrict the callback URL to authenticated requests and manually implement signature checks to prevent unauthorized access.

Generated by OpenCVE AI on September 18, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Autopay
Autopay autopay
Wordpress
Wordpress wordpress
Vendors & Products Autopay
Autopay autopay
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.
Title Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion
References

Subscriptions

Autopay Autopay
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:27:14.153Z

Reserved: 2026-09-14T11:12:21.172Z

Link: CVE-2026-90923

cve-icon Vulnrichment

Updated: 2026-09-17T12:10:31.995Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.423

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-90923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses