CVE-2026-62111: WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability
Published Sep 11, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.
Affected Software
1 affected component
WordPress Simple Payment plugin<=2.5.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simple Payment Pluginto a version that resolves this vulnerability.Fixed in 2.5.6
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using the affected plugin. Exploitation also requires a user to interact with the attacker-controlled content.
2
Which plugin versions are affected?
Simple Payment versions 2.5.4 and earlier are affected.
3
What is the potential impact?
Successful exploitation can allow cross-site scripting in the context of a user who views or interacts with the malicious content, with low confidentiality, integrity, and availability impact and a changed scope.