VYPR

Autopay WordPress plugin

by WordPress

CVEs (1)

  • CVE-2026-14293HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that…