Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway
CVE-2026-73398

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-73398?

An unauthenticated broken authentication vulnerability exists in version 3.2.0 of the Piraeus Bank WooCommerce Payment Gateway. This flaw may allow attackers to exploit the authentication mechanism, potentially leading to unauthorized access and compromising user accounts. It is critical for users to update to the latest version and apply recommended security measures to safeguard their WordPress sites.

Affected Version(s)

Piraeus Bank WooCommerce Payment Gateway 3.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.