Junglewise Threat Intelligence

CVE-2026-56024: Saad Iqbal WP EasyPay CSRF in WordPress plugin

CVE-2026-56024 · Severity: medium · CVSS 6.5 · Published 2026-06-18

Technologies: Saad Iqbal WP EasyPay. Vendors: Saad Iqbal.

Executive brief

WP EasyPay is a WordPress plugin used to facilitate payments and transactions on websites. A security flaw allows an attacker to trick a logged-in administrator into performing unintended actions without their knowledge. This could lead to unauthorized changes in payment settings or site configuration, potentially disrupting business operations or financial workflows.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Saad Iqbal WP EasyPay plugin for WordPress through version 4.4.0. The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections in sensitive administrative functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator to visit a malicious webpage or click a crafted link. Successful exploitation allows the attacker to execute unauthorized actions with the privileges of the victim, such as modifying plugin settings. At the time of the advisory, no official patch has been confirmed.

Affected products

  • Saad Iqbal WP EasyPay up to 4.4.0

Timeline

  • 2026-03-20: other: Reported by Sajjad Haqi
  • 2026-06-18: advisory: Published by Patchstack and NVD

References

Related threats