CVE-2026-78260: WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability
Published Aug 27, 2026
·Updated
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Affected Software
1 affected component
WordPress Epayco plugin<=8.4.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Epayco pluginto a version that resolves this vulnerability.Fixed in 8.4.7
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
Which installations should be treated as affected?
WordPress sites using the Epayco plugin version 8.4.6 or earlier should be treated as affected based on the available information.
3
What is the likely security impact?
The vulnerability is SQL injection and is rated critical with high confidentiality impact. Successful exploitation may expose data accessible through the affected application's database queries.