VYPR

elegro Crypto Payment

by WordPress

CVEs (1)

  • CVE-2026-94299Oct 6, 2026
    risk 0.00cvss —epss —

    The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any…