Executive brief
WP Easy Pay, a WordPress plugin used to create payment and donation forms, contains a security flaw that allows low-level users to unpublish website content. An attacker with a basic account can change the status of any post or page to 'draft' mode. This can lead to business disruption by making critical site information or donation forms invisible to the public.
Technical details
The WP Easy Pay plugin for WordPress suffers from a missing authorization check (CWE-862) in its handling of post status updates. The vulnerability exists in versions up to and including 4.5.0. An authenticated attacker with at least subscriber-level permissions can exploit this flaw via a network request to change the status of any arbitrary post or page to 'draft'. This occurs because the plugin fails to verify if the requesting user has the appropriate administrative rights to modify post statuses. A patch appears to be available in versions following 4.5.0 based on changeset references.
Affected products
- saadiqbal WP Easy Pay – Payment and Donation form Builder for Square Up to, and including, 4.5.0
Timeline
- 2026-07-11: disclosed: CVE published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/wp-easy-pay/tags/4.5.0/wpep-setup.php
- https://plugins.trac.wordpress.org/browser/wp-easy-pay/tags/4.5.0/wpep-setup.php
- https://plugins.trac.wordpress.org/browser/wp-easy-pay/tags/4.5.0/wpep-setup.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3593500%40wp-easy-pay&new=3593500%40wp-easy-pay
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2121d9fa-bab4-489d-89bc-07a8660bc3d1?source=cve