CVE-2026-73338: WordPress Autopay plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Affected Software
1 affected component
wordpress/Autopay plugin<=5.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Autopay pluginto a version that resolves this vulnerability.Fixed in 5.0.1
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be considered exposed?
Sites using Autopay version 5.0.0 or earlier are affected according to the available data. The issue is in the WordPress Autopay plugin, not WordPress generally.
2
What does an attacker need to exploit this vulnerability?
An attacker does not need authentication and can exploit the issue over the network with low attack complexity, but user interaction is required. Successful exploitation can affect confidentiality, integrity, and availability at low impact.