Codepress · Nowpayments For Woocommerce · CVE-2026-39448
**Name of the Vulnerable Software and Affected Versions**
NOWPayments for WooCommerce versions prior to 1.4.1
**Description**
The NOWPayments for WooCommerce – Crypto Payment Gateway plugin for WordPress contains a broken access control flaw. This issue occurs because of a missing capability check within a function, allowing unauthenticated attackers to perform unauthorized actions.
**Recommendations**
Update the plugin to a version later than 1.4.0.