CVE-2026-61978: WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) Pluginto a version that resolves this vulnerability.Fixed in 1.0.33
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61978?
The severity of CVE-2026-61978 is classified as medium with a score of 6.5.
How do I fix CVE-2026-61978?
To fix CVE-2026-61978, update the Secure Card Gateway for ePay Paycenter plugin to version 1.0.33 or later.
What type of vulnerability is CVE-2026-61978?
CVE-2026-61978 is an unauthenticated Broken Access Control vulnerability.
Which versions of the WordPress plugin are affected by CVE-2026-61978?
Versions of the Secure Card Gateway for ePay Paycenter plugin prior to 1.0.33 are affected by CVE-2026-61978.
Who is the vendor of the Secure Card Gateway for ePay Paycenter plugin related to CVE-2026-61978?
The vendor of the Secure Card Gateway for ePay Paycenter plugin is Piraeus Bank.