CVE-2026-96818: WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Express Checkout (Accept PayPal Payments) pluginto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit the affected plugin.
Which installations should be considered affected?
Installations using WP Express Checkout (Accept PayPal Payments) version 2.4.9 or earlier should be considered affected based on the available data.
What security impact is indicated?
The reported impact is high integrity impact, meaning successful exploitation may allow unauthorized modification of data or application state. No confidentiality or availability impact is indicated.