WP EasyPay
by WordPress
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-56024 | Med | 0.42 | 6.5 | 0.00 | Jun 18, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0. | ||
| CVE-2023-1465 | Med | 0.40 | 6.1 | 0.00 | Aug 16, 2023 | The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin | ||
| CVE-2026-32587 | Med | 0.35 | 5.4 | 0.00 | Mar 16, 2026 | Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11. | ||
| CVE-2026-84762 | Med | 0.34 | 5.3 | 0.00 | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | ||
| CVE-2026-45215 | Med | 0.34 | 5.3 | 0.00 | May 12, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0. | ||
| CVE-2024-5861 | Med | 0.34 | 5.3 | 0.00 | Jul 24, 2024 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated… | ||
| CVE-2021-4411 | Med | 0.28 | 4.3 | 0.00 | Jul 12, 2023 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for… | ||
| CVE-2022-47177 | Med | 0.28 | 4.3 | 0.00 | May 25, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions. | ||
| CVE-2026-57808 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. | ||
| CVE-2026-12738 | Med | 0.00 | 4.3 | 0.00 | Jul 11, 2026 | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… |
- risk 0.42cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.
- risk 0.40cvss 6.1epss 0.00
The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
- risk 0.34cvss 5.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.
- risk 0.34cvss 5.3epss 0.00
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated…
- risk 0.28cvss 4.3epss 0.00
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for…
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
- risk 0.00cvss 4.3epss 0.00
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…