Payment Notification Vulnerability in UnitechPay WordPress Plugin
CVE-2026-87841

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-87841?

The UnitechPay WordPress plugin version 1.0.6.3 suffers from a significant flaw where it fails to authenticate payment notifications. This vulnerability allows attackers to mark orders as paid without any legitimate payment being processed, in addition to the ability to arbitrarily change the status of other orders to failed. Such exploitation can lead to severe financial losses and undermine the trust in transaction integrity within your site.

Affected Version(s)

UnitechPay 0 <= 1.0.6.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Timur
WPScan
.