Executive brief
MyCryptoCheckout is a WordPress plugin that allows website owners to accept cryptocurrency payments directly. A security flaw in the plugin's access control settings allows unauthorized individuals to bypass security checks. This could lead to the exposure of sensitive transaction data or unauthorized access to payment-related functions, potentially impacting the integrity of the store's financial operations.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the MyCryptoCheckout plugin for WordPress through version 2.161. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before granting access to specific functions or data. An unauthenticated remote attacker can exploit this by sending crafted network requests to the affected site. Successful exploitation allows the attacker to bypass intended security restrictions and potentially access sensitive information (CVSS C:H). The issue is resolved in version 2.162.
Affected products
- Edward Plainview MyCryptoCheckout <= 2.161
Timeline
- 2026-01-19: other: Reported by Nguyen Ba Khanh
- 2026-05-12: advisory: Patchstack advisory published
- 2026-05-25: disclosed: NVD publication date
- 2026-05-12: patched: Version 2.162 released