Junglewise Threat Intelligence

CVE-2026-12739: WP Easy Pay authorization bypass in post operations

CVE-2026-12739 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Executive brief

WP Easy Pay is a WordPress plugin for building payment and donation forms that integrate with Square. A flaw in the plugin allows authenticated WordPress users with basic subscriber-level permissions to bypass security checks and delete any posts or pages on the site, or downgrade published content to draft status, regardless of their intended access rights.

Technical details

The plugin contains an authorization bypass vulnerability due to insufficient permission verification when processing post-related actions. Authenticated attackers with subscriber-level access and above can exploit this flaw to perform unauthorized operations including force deletion of arbitrary posts, pages, and custom post types (bypassing WordPress trash), and downgrading published posts to draft status. The vulnerability is present in all versions up to and including 4.5.0. No patch status is specified in the advisory.

Affected products

  • WP Easy Pay WP Easy Pay up to and including 4.5.0

Timeline

  • 2026-09-18: disclosed

References