CVE-2026-81767
—Unauthenticated Broken Access Control in Simple Payment WordPress Plugin
CVE-2026-81767 is a missing authorization flaw (CWE-862) in the Simple Payment WordPress plugin, affecting all versions through 2.5.2. Because the affected functionality does not verify that a request is authorized, an unauthenticated remote attacker can trigger it simply by sending crafted HTTP requests to the vulnerable endpoints, with no user interaction or credentials required. Per the CVSS vector, the impact is to data integrity only (no confidentiality or availability loss), meaning an attacker can modify data or settings without reading or disrupting the site. Any WordPress site running Simple Payment version 2.5.2 or earlier is affected. There is currently no known exploitation in the wild, no public proof-of-concept, and the EPSS probability of exploitation within 30 days is low at 0.2%.
What to do: Administrators running Simple Payment 2.5.2 or earlier should update to the first patched release after 2.5.2 as soon as it is available (a specific fixed version was not included in the available data). Until the site is patched, consider deactivating the plugin or restricting unauthenticated access to the site, and review web server logs for unexpected unauthenticated requests to the plugin's endpoints. Monitor the plugin's WordPress.org page or the Patchstack advisory for the fixed version and any newly published proof-of-concept.
| Simple Payment (WordPress plugin) | <= 2.5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.