CVE-2026-14293: Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14293?
The severity of CVE-2026-14293 is rated as 62, indicating a moderate risk level for users.
How do I fix CVE-2026-14293?
To fix CVE-2026-14293, upgrade the Autopay plugin to version 5.0.1 or later.
What type of vulnerability is CVE-2026-14293?
CVE-2026-14293 is classified as an Unauthenticated Stored XSS vulnerability caused by inadequate checks in the Autopay plugin.
Who is affected by CVE-2026-14293?
Any user of the Autopay plugin for WooCommerce versions prior to 5.0.1 is affected by CVE-2026-14293.
What can attackers do with CVE-2026-14293?
Attackers exploiting CVE-2026-14293 can store JavaScript that executes in users' browsers during the checkout process.