CVE-2026-95527
6.5Conekta Group · Conekta Payment Gateway
A missing authorization flaw in the Conekta Payment Gateway plugin allows unauthenticated attackers to perform unauthorized actions via broken access control.
Executive summary
The Conekta Payment Gateway plugin for WordPress contains an unauthenticated broken access control vulnerability that permits unauthorized modifications to system operations.
Vulnerability
This vulnerability is a missing authorization flaw (CWE-862) that allows an unauthenticated attacker to bypass access controls and perform restricted actions within the plugin.
Business impact
Successful exploitation of this vulnerability could lead to unauthorized integrity loss within the payment gateway configuration or transaction flow. Given the CVSS score of 6.5, the risk is categorized as Medium, but the potential for unauthorized administrative actions in a payment-processing environment presents a significant risk to financial data integrity and business operations.
Remediation
Immediate Action: Update the WordPress Conekta Payment Gateway plugin to version 6.2.5 or later immediately.
Proactive Monitoring: Review web server and application access logs for unexpected requests to plugin-specific endpoints or unauthorized changes to payment configurations.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious or unauthorized requests targeting the plugin's administrative or configuration-related endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The vulnerability poses a clear risk to the integrity of payment processing workflows. Administrators must prioritize updating to version 6.2.5 or higher to eliminate this access control weakness. Failure to patch may expose the application to unauthorized configuration changes and potential disruption of payment services.
History
- Analyst report written
Sources
Originally found and disclosed by anhcd05 | Patchstack Bug Bounty Program, per the CVE Program record.