Unauthenticated Broken Access Control in Xendit Payment Plugin by Xendit
CVE-2026-66473

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

What is CVE-2026-66473?

The Xendit Payment Plugin is susceptible to an unauthenticated broken access control vulnerability. This flaw allows attackers to exploit the plugin versions up to 7.1.0, potentially gaining unauthorized access to sensitive functionalities. As a result, improper access controls can lead to unauthorized transaction processing, impacting both user data security and overall system integrity. It is crucial for users of affected versions to update promptly to maintain security.

Affected Version(s)

Xendit Payment <= 7.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mitchell | Patchstack Bug Bounty Program
.