VYPR

Autopay

by WordPress

CVEs (1)

  • CVE-2026-14293Aug 10, 2026
    risk 0.00cvss epss

    The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that…