ZeroHour

CVE-2026-81292

niche

Unauthenticated Cross-Site Scripting (XSS) in Simple Payment WordPress Plugin (<= 2.5.1)

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81292 is an unauthenticated cross-site scripting flaw (CWE-79) in the Simple Payment WordPress plugin, affecting all versions up to and including 2.5.1. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C) indicates the attack is network-reachable, requires no privileges, and only needs user interaction, meaning an unauthenticated attacker can supply malicious script input that executes in a victim's browser when the affected page is viewed or interacted with. Successful exploitation could allow arbitrary JavaScript to run in the context of the site (changed scope), potentially enabling actions such as stealing page or session data, redirecting visitors, or tampering with page content, though CVSS rates confidentiality, integrity, and availability impacts as low. Any WordPress site running Simple Payment 2.5.1 or earlier is affected, with actual exposure depending on whether the vulnerable component is reachable by unauthenticated visitors. No public proof of concept, in-the-wild exploitation, or CISA KEV listing is currently known, and EPSS assigns only about a 0.2% (8th percentile) chance of exploitation within the next 30 days.

What to do: Update Simple Payment to the latest patched release (any version newer than 2.5.1; check the plugin page or the Patchstack advisory for the exact fixed version). Until patched, consider temporarily deactivating the plugin if it is not essential to your payment or donation flow, and consider WAF or virtual-patching rules that block unauthenticated XSS against the plugin's endpoints. After updating, review recent site activity for signs of injected scripts.

Affected
Simple Payment<= 2.5.1 (all versions up to and including 2.5.1)
Estimated exposure
nichelikely low hundreds to low thousands of WordPress sites (estimate; no install count provided in source data) — No active-install figure was supplied for this niche WordPress payment plugin, so the estimate reflects the typical small install base of minor plugins rather than a verified count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.