CVE-2026-66461: WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypass vulnerability
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SMEPay: UPI Gateway for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 1.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66461?
The severity of CVE-2026-66461 is classified as high, with a score of 7.5.
What does CVE-2026-66461 entail?
CVE-2026-66461 describes an unauthenticated broken access control vulnerability in the SMEPay: UPI Gateway for WooCommerce plugin versions up to 1.0.5.
How do I fix CVE-2026-66461?
To fix CVE-2026-66461, upgrade the SMEPay: UPI Gateway for WooCommerce plugin to the latest version after 1.0.5.
Who is affected by CVE-2026-66461?
Any user of the SMEPay: UPI Gateway for WooCommerce plugin version 1.0.5 or earlier is at risk from CVE-2026-66461.
Can CVE-2026-66461 lead to data breaches?
Yes, because it allows attackers to bypass payment processes, CVE-2026-66461 could potentially lead to unauthorized transactions.