Junglewise Threat Intelligence

CVE-2026-39650: Unitech Web UnitechPay missing authorization in WordPress plugin

CVE-2026-39650 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

UnitechPay is a WordPress plugin used to facilitate mobile money payments. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes to payment configurations or other sensitive settings, potentially impacting financial transactions or site operations.

Technical details

The UnitechPay plugin (unitechpay-paiements-mobile-money) for WordPress suffers from a Missing Authorization (CWE-862) vulnerability. The flaw exists due to incorrectly configured access control security levels within the plugin's functional components. A remote, unauthenticated attacker can exploit this by sending crafted requests to affected endpoints, allowing them to execute actions or access data that should require higher privilege levels. As of the advisory date, no official patch has been confirmed, and the vulnerability affects versions up to and including 1.0.2.

Affected products

  • Unitech Web UnitechPay (unitechpay-paiements-mobile-money) <= 1.0.2

Timeline

  • 2026-01-16: other: Vulnerability reported by researcher Ngo Bui Truong Vu
  • 2026-02-15: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE-2026-39650 published to NVD

References