Junglewise Threat Intelligence

CVE-2026-42763: SePay Gateway missing authorization in WordPress plugin

CVE-2026-42763 · Severity: medium · CVSS 6.5 · Published 2026-05-25

Executive brief

SePay Gateway is a WordPress plugin used to process payments on e-commerce websites. A security flaw in this plugin allows unauthorized individuals to access sensitive data that should be protected. This could lead to the exposure of private transaction details or configuration information, potentially aiding further attacks against the website or its customers.

Technical details

The SePay Gateway plugin for WordPress (versions up to 1.1.20) suffers from a missing authorization vulnerability (CWE-862). This flaw allows an attacker with low-level privileges (subscriber or similar) to bypass intended access controls and retrieve sensitive information embedded within the application. The vulnerability is exploitable over the network without user interaction. The issue is resolved in version 1.1.21, which implements proper authorization checks to prevent unauthorized data access.

Affected products

  • SePay team SePay Gateway n/a through 1.1.20

Timeline

  • 2026-05-03: other: Reported by ParkHyunWoo
  • 2026-05-25: disclosed: CVE published to NVD
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-02: patched: Version 1.1.21 released

References