Subscriber Bypass Vulnerability in MicroPayments Plugin by WordPress
CVE-2026-107434

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-107434?

The MicroPayments plugin for WordPress has a critical security flaw that allows unauthorized users to bypass subscriber access controls. This vulnerability affects versions 3.2.9 and earlier, potentially enabling attackers to gain access to restricted content and features, compromising the integrity and confidentiality of users' data. It is essential for website administrators using affected versions to apply updates and patches promptly to mitigate this security threat.

Affected Version(s)

MicroPayments <= 3.2.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JunHee CHO | Patchstack Bug Bounty Program
.