CVE-2026-95527: WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Conekta Payment Gateway pluginto a version that resolves this vulnerability.Fixed in 6.2.5
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
What is the potential impact?
The reported CVSS vector indicates low impacts to integrity and availability, with no reported confidentiality impact. The issue is rated medium severity with a CVSS score of 6.5.
Which installations are known to be affected?
Conekta Payment Gateway plugin versions 6.2.4 and earlier are listed as affected. The provided information does not state whether a particular WordPress or plugin configuration is required.