ZeroHour

CVE-2026-81767

Unauthenticated Broken Access Control in Simple Payment WordPress Plugin

CVSS 3.1
7.5 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-81767 is a missing authorization flaw (CWE-862) in the Simple Payment WordPress plugin, affecting all versions through 2.5.2. Because the affected functionality does not verify that a request is authorized, an unauthenticated remote attacker can trigger it simply by sending crafted HTTP requests to the vulnerable endpoints, with no user interaction or credentials required. Per the CVSS vector, the impact is to data integrity only (no confidentiality or availability loss), meaning an attacker can modify data or settings without reading or disrupting the site. Any WordPress site running Simple Payment version 2.5.2 or earlier is affected. There is currently no known exploitation in the wild, no public proof-of-concept, and the EPSS probability of exploitation within 30 days is low at 0.2%.

What to do: Administrators running Simple Payment 2.5.2 or earlier should update to the first patched release after 2.5.2 as soon as it is available (a specific fixed version was not included in the available data). Until the site is patched, consider deactivating the plugin or restricting unauthenticated access to the site, and review web server logs for unexpected unauthenticated requests to the plugin's endpoints. Monitor the plugin's WordPress.org page or the Patchstack advisory for the fixed version and any newly published proof-of-concept.

Affected
Simple Payment (WordPress plugin)<= 2.5.2
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.