Junglewise Threat Intelligence

CVE-2026-45215: Saad Iqbal WP EasyPay sensitive data exposure

CVE-2026-45215 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Technologies: Saad Iqbal WP EasyPay. Vendors: Saad Iqbal.

Executive brief

WP EasyPay, a WordPress plugin used for processing payments, contains a security flaw that may expose sensitive information to unauthorized users. An attacker could exploit this to view data that should be protected, potentially leading to further attacks or privacy breaches. This issue affects all versions up to 4.3.0 and is resolved in version 4.4.0.

Technical details

The WP EasyPay plugin for WordPress (versions <= 4.3.0) is vulnerable to CWE-201: Insertion of Sensitive Information Into Sent Data. This vulnerability allows an unauthenticated remote attacker to retrieve sensitive information that is embedded in data sent by the application. The root cause is the improper handling of sensitive data within the plugin's output or communication channels. An attacker can exploit this over the network without any user interaction. The issue is addressed in version 4.4.0.

Affected products

  • Saad Iqbal WP EasyPay <= 4.3.0

Timeline

  • 2026-03-09: other: Vulnerability reported by researcher sleeper
  • 2026-04-08: patched: Patch released in version 4.4.0
  • 2026-05-12: disclosed: CVE-2026-45215 published

References

Related threats