CVE-2026-39650
Description
Missing Authorization vulnerability in Unitech Web UnitechPay unitechpay-paiements-mobile-money allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnitechPay: from n/a through <= 1.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing authorization vulnerability in UnitechPay (≤1.0.2) allows unauthenticated attackers to exploit incorrectly configured access controls.
Vulnerability
Overview
The UnitechPay plugin for WordPress (versions up to and including 1.0.2) suffers from a missing authorization vulnerability [1]. The root cause is an incorrectly configured access control that does not properly check user permissions or nonce tokens before allowing access to sensitive functions. This flaw falls under the category of broken access control, where security levels are incorrectly configured [1].
Exploitation
An attacker can exploit this vulnerability without needing any prior authentication or special privileges. The attack vector is over the network, and the lack of proper access control checks means that unprivileged users or even unauthenticated visitors can trigger the vulnerable functions [1]. No user interaction is required to exploit this issue.
Impact
Successful exploitation could allow an attacker to perform actions that should be restricted to higher-privileged roles, such as modifying plugin settings or accessing sensitive data or accessing protected features. While the CVSS score (5.3) indicates medium severity, this vulnerability is especially concerning because it can be used in mass-exploit campaigns against thousands of WordPress sites [1].
Mitigation
The vendor has not released a patched version at the time of disclosure. Users are strongly advised to update the plugin as soon as a patch becomes available. If an immediate update is not possible, it is recommended to disable the plugin or seek assistance from a hosting provider or web developer [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.