Unauthenticated Broken Access Control in Autopay for WooCommerce by WordPress
CVE-2026-57425

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-57425?

The Autopay plugin for WooCommerce versions up to 2.2.27 is susceptible to an unauthenticated broken access control vulnerability, allowing unauthorized users to exploit access restrictions. This flaw can potentially lead to serious data exposure and unauthorized actions within the WooCommerce environment, posing a significant risk to ecommerce operators using this plugin.

Affected Version(s)

Autopay dla WooCommerce <= 2.2.27

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Averon Averenkov | Patchstack Bug Bounty Program
.