VYPR

WP EasyPay

by WordPress

CVEs (10)

  • CVE-2026-56024MedJun 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.

  • CVE-2023-1465MedAug 16, 2023
    risk 0.40cvss 6.1epss 0.00

    The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

  • CVE-2026-32587MedMar 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.

  • CVE-2026-84762MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.

  • CVE-2026-45215MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.

  • CVE-2024-5861MedJul 24, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated…

  • CVE-2021-4411MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.00

    The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for…

  • CVE-2022-47177MedMay 25, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions.

  • CVE-2026-57808MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

  • CVE-2026-12738MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…