CVE-2026-81292: WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.
Affected Software
1 affected component
WordPress Simple Payment plugin<=2.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simple Payment pluginto a version that resolves this vulnerability.Fixed in 2.5.2
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so the attacker does not need a WordPress account or prior privileges. Exploitation does require user interaction.
2
Which plugin versions are affected?
Simple Payment versions 2.5.1 and earlier are affected. The provided data does not identify a fixed version.
3
What impact could successful exploitation have?
The CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. As an XSS issue, successful exploitation can affect users who interact with attacker-supplied content.