PT-2026-69344 · WordPress · Autopay
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autopay WordPress plugin versions prior to 5.0.1
Description
An issue exists where the software fails to perform capability or nonce checks before saving a styling option from a public request. Additionally, the saved value is not escaped when output on the checkout page. This allows unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page. A nonce is a unique token used to prevent replay attacks by ensuring that a request is intentional and comes from a trusted source.
Recommendations
Update Autopay WordPress plugin to version 5.0.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autopay