Authorization Bypass in WP Easy Pay Plugin for WordPress
CVE-2026-12739
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-12739?
The WP Easy Pay plugin, designed for payment and donation forms on WordPress, contains a serious vulnerability that allows unauthorized users with subscriber-level access or higher to bypass authorization checks. This oversight enables them to delete posts, pages, and custom post types permanently or change the status of published posts to drafts. Without adequate user permission verification, legitimate subscribers may exploit this weakness to manipulate content on affected sites, posing a significant risk to data integrity.
Affected Version(s)
WP Easy Pay β Payment and Donation Form Builder for Square 0 <= 4.5.0