CVE-2026-81292
nicheUnauthenticated Cross-Site Scripting (XSS) in Simple Payment WordPress Plugin (<= 2.5.1)
CVE-2026-81292 is an unauthenticated cross-site scripting flaw (CWE-79) in the Simple Payment WordPress plugin, affecting all versions up to and including 2.5.1. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C) indicates the attack is network-reachable, requires no privileges, and only needs user interaction, meaning an unauthenticated attacker can supply malicious script input that executes in a victim's browser when the affected page is viewed or interacted with. Successful exploitation could allow arbitrary JavaScript to run in the context of the site (changed scope), potentially enabling actions such as stealing page or session data, redirecting visitors, or tampering with page content, though CVSS rates confidentiality, integrity, and availability impacts as low. Any WordPress site running Simple Payment 2.5.1 or earlier is affected, with actual exposure depending on whether the vulnerable component is reachable by unauthenticated visitors. No public proof of concept, in-the-wild exploitation, or CISA KEV listing is currently known, and EPSS assigns only about a 0.2% (8th percentile) chance of exploitation within the next 30 days.
What to do: Update Simple Payment to the latest patched release (any version newer than 2.5.1; check the plugin page or the Patchstack advisory for the exact fixed version). Until patched, consider temporarily deactivating the plugin if it is not essential to your payment or donation flow, and consider WAF or virtual-patching rules that block unauthenticated XSS against the plugin's endpoints. After updating, review recent site activity for signs of injected scripts.
| Simple Payment | <= 2.5.1 (all versions up to and including 2.5.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.