Description
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Published: 2026-09-23
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Potential unauthenticated modification of payment settings and data
Action: Patch Now
AI Analysis

Impact

An unauthenticated broken access control flaw exists in the Conekta Payment Gateway WordPress plugin prior to version 6.2.5, allowing an attacker that can reach the plugin’s administration endpoints to modify payment gateway configuration or initiate payment operations without authentication. If exploited, the attacker could misconfigure payment parameters, redirect funds, or interfere with transaction processing, leading to financial loss or service disruption. The weakness is a classic authorization bypass (CWE‑862).

Affected Systems

WordPress sites using the Conekta Payment Gateway plugin version 6.2.4 or earlier are affected. The plugin is authored by the Conekta Group under the Conekta Payment Gateway brand.

Risk and Exploitability

The CVSS base score is 6.5, indicating a moderate impact that may compromise confidentiality and integrity of payment data. The EPSS score is unavailable, but no public exploits or KEV listing exist, suggesting no widespread active exploitation. The vulnerability requires no special privileges and can be triggered via standard web requests to the plugin’s admin interface, making it likely susceptible to remote exploitation from any network that can reach the WordPress installation.

Generated by OpenCVE AI on September 23, 2026 at 20:29 UTC.

Remediation

Vendor Solution

Update the WordPress Conekta Payment Gateway plugin to the latest available version (at least 6.2.5).


OpenCVE Recommended Actions

  • Update the WordPress Conekta Payment Gateway plugin to version 6.2.5 or later, which removes the unauthenticated access control flaw.
  • Disable or uninstall the plugin if payment gateway functionality is not required.
  • Restrict HTTP access to the plugin’s admin endpoints to a trusted IP range or VPN only.

Generated by OpenCVE AI on September 23, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Conekta Group
Conekta Group conekta Payment Gateway
Wordpress
Wordpress wordpress
Vendors & Products Conekta Group
Conekta Group conekta Payment Gateway
Wordpress
Wordpress wordpress

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Title WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Conekta Group Conekta Payment Gateway
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T18:46:51.553Z

Reserved: 2026-09-22T08:50:55.122Z

Link: CVE-2026-95527

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:51.967

Modified: 2026-09-23T19:39:08.847

Link: CVE-2026-95527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T21:15:09Z

Weaknesses