CVE-2026-81767: WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simple Payment Pluginto a version that resolves this vulnerability.Fixed in 2.5.3
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any existing privileges. The CVSS vector indicates it is remotely reachable, requires low attack complexity, and does not require user interaction.
What is the likely security impact?
The reported impact is integrity-only: an attacker may be able to perform unauthorized modifications through the affected access-control weakness. No confidentiality or availability impact is indicated by the provided CVSS vector.
Which installations are affected?
WordPress sites using the Simple Payment plugin version 2.5.2 or earlier are affected according to the available information. The data does not state whether any particular plugin configuration or feature must be enabled.