CVE-2026-94179: WordPress Razorpay Payment Button plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Razorpay Payment Button pluginto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or other prior authentication to attempt exploitation. Successful exploitation still requires user interaction, as indicated by the UI:R vector.
What versions are affected?
Razorpay Payment Button versions 2.4.9 and earlier are identified as affected. The provided data does not identify a fixed version.
What is the potential impact?
The CVSS vector indicates low-impact compromise of confidentiality, integrity, and availability, with scope changed. As an XSS issue, exploitation may allow attacker-controlled script execution in a victim's browser context.