CVE-2026-95527

6.5

Conekta Group · Conekta Payment Gateway

A missing authorization flaw in the Conekta Payment Gateway plugin allows unauthenticated attackers to perform unauthorized actions via broken access control.

Executive summary

The Conekta Payment Gateway plugin for WordPress contains an unauthenticated broken access control vulnerability that permits unauthorized modifications to system operations.

Vulnerability

This vulnerability is a missing authorization flaw (CWE-862) that allows an unauthenticated attacker to bypass access controls and perform restricted actions within the plugin.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized integrity loss within the payment gateway configuration or transaction flow. Given the CVSS score of 6.5, the risk is categorized as Medium, but the potential for unauthorized administrative actions in a payment-processing environment presents a significant risk to financial data integrity and business operations.

Remediation

Immediate Action: Update the WordPress Conekta Payment Gateway plugin to version 6.2.5 or later immediately.

Proactive Monitoring: Review web server and application access logs for unexpected requests to plugin-specific endpoints or unauthorized changes to payment configurations.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious or unauthorized requests targeting the plugin's administrative or configuration-related endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

The vulnerability poses a clear risk to the integrity of payment processing workflows. Administrators must prioritize updating to version 6.2.5 or higher to eliminate this access control weakness. Failure to patch may expose the application to unauthorized configuration changes and potential disruption of payment services.

History

  1. Analyst report written

Sources

Originally found and disclosed by anhcd05 | Patchstack Bug Bounty Program, per the CVE Program record.