CVE-2026-66431: WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)to a version that resolves this vulnerability.Fixed in 1.0.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66431?
The severity of CVE-2026-66431 is classified as high with a score of 7.5.
What type of vulnerability is CVE-2026-66431?
CVE-2026-66431 is an unauthenticated Broken Access Control vulnerability.
How do I fix CVE-2026-66431?
To fix CVE-2026-66431, update the Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin to the latest version beyond 1.0.7.
What software is affected by CVE-2026-66431?
CVE-2026-66431 affects the WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin version 1.0.7 and below.
What impact does CVE-2026-66431 have on my WordPress site?
CVE-2026-66431 allows unauthorized access to functionalities, which can lead to data manipulation or exploitation of your WordPress site.