Authorization Bypass in WP Easy Pay Plugin for WordPress
CVE-2026-12739

4.3MEDIUM

What is CVE-2026-12739?

The WP Easy Pay plugin, designed for payment and donation forms on WordPress, contains a serious vulnerability that allows unauthorized users with subscriber-level access or higher to bypass authorization checks. This oversight enables them to delete posts, pages, and custom post types permanently or change the status of published posts to drafts. Without adequate user permission verification, legitimate subscribers may exploit this weakness to manipulate content on affected sites, posing a significant risk to data integrity.

Affected Version(s)

WP Easy Pay – Payment and Donation Form Builder for Square 0 <= 4.5.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.