CVE-2026-93620

6.5

PayPlus Tech Team · PayPlus Payment Gateway

The PayPlus Payment Gateway plugin for WordPress contains an unauthenticated broken access control vulnerability in versions 8.2.5 and earlier.

Executive summary

An unauthenticated broken access control vulnerability in the PayPlus Payment Gateway plugin allows unauthorized users to perform sensitive actions without proper authorization.

Vulnerability

The plugin suffers from a missing authorization flaw (CWE-862) that permits unauthenticated remote attackers to interact with restricted functionality. This flaw occurs because the application fails to perform necessary capability checks before processing incoming requests.

Business impact

The ability for unauthenticated parties to bypass access controls presents a significant risk to payment processing integrity and data confidentiality. While the CVSS score of 6.5 characterizes this as a medium severity issue, the exposure of payment gateway configurations or transaction data could lead to direct financial loss and regulatory non-compliance for businesses.

Remediation

Immediate Action: Update the PayPlus Payment Gateway plugin to version 8.2.6 or the latest available version immediately.

Proactive Monitoring: Review web server and application access logs for unusual patterns or requests targeting gateway configuration endpoints from unauthorized IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to block unauthorized access to plugin-specific administrative or configuration endpoints until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the PayPlus Payment Gateway plugin must prioritize applying the vendor-supplied patch to version 8.2.6. Given the nature of payment processing software, maintaining strict authorization boundaries is essential to preventing unauthorized modification of transaction flows and protecting sensitive customer information.

History

  1. Analyst report written

Sources

Originally found and disclosed by mamgad | Patchstack Bug Bounty Program, per the CVE Program record.