VYPR

STRABL

by WordPress

CVEs (1)

  • CVE-2026-3640Jun 19, 2026
    risk 0.00cvss epss

    The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_callback of __return_true, which allows…