Unauthenticated Broken Access Control in Autopay for WooCommerce by WordPress
CVE-2026-57425
6.5MEDIUM
What is CVE-2026-57425?
The Autopay plugin for WooCommerce versions up to 2.2.27 is susceptible to an unauthenticated broken access control vulnerability, allowing unauthorized users to exploit access restrictions. This flaw can potentially lead to serious data exposure and unauthorized actions within the WooCommerce environment, posing a significant risk to ecommerce operators using this plugin.
Affected Version(s)
Autopay dla WooCommerce <= 2.2.27