CVE-2026-45215: WordPress WP EasyPay plugin <= 4.3.0 - Sensitive Data Exposure vulnerability
Published May 12, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.
Affected Software
1 affected component
Saad Iqbal WP EasyPay<=4.3.0
Event History
May 12, 2026
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-45215?
CVE-2026-45215 is classified as a moderate severity vulnerability due to its potential for sensitive data exposure.
2
How do I fix CVE-2026-45215?
To fix CVE-2026-45215, upgrade the WP EasyPay plugin to the latest version beyond 4.3.0.
3
What type of vulnerability is CVE-2026-45215?
CVE-2026-45215 is a sensitive data exposure vulnerability that allows the retrieval of embedded sensitive data.
4
Which versions of WP EasyPay are affected by CVE-2026-45215?
CVE-2026-45215 affects all versions of WP EasyPay up to and including version 4.3.0.
5
Who is the vendor of the affected software in CVE-2026-45215?
The vendor of the affected software in CVE-2026-45215 is Saad Iqbal.