Authorization Bypass Vulnerability in SePay Gateway by SePay Team
CVE-2026-42763

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 May 2026

What is CVE-2026-42763?

The SePay Gateway developed by SePay Team contains a missing authorization vulnerability that permits unauthorized retrieval of embedded sensitive data. This security flaw affects all versions of the SePay Gateway up to 1.1.20, posing risks of data exposure. It is critical for users to evaluate their systems and apply necessary mitigations to protect sensitive information from unauthorized access.

Affected Version(s)

SePay Gateway <= 1.1.20

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ParkHyunWoo | Patchstack Bug Bounty Program
.