Executive brief
A critical security vulnerability has been identified in the '워드프레스 결제 심플페이' (Simple Pay) plugin for WordPress, which is used to process payments on e-commerce websites. An attacker can exploit this flaw to gain unauthorized access to the website's database without needing a username or password. This could lead to the theft of sensitive customer information, payment data, or a complete compromise of the online store's operations.
Technical details
The 워드프레스 결제 심플페이 (pgall-for-woocommerce) plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). The flaw exists in versions up to and including 5.5.6. A remote, unauthenticated attacker can exploit this by sending specially crafted web requests to the affected WordPress site, allowing them to bypass authentication and directly interact with the underlying database. This can result in full data exfiltration or unauthorized modification of database records. The issue is resolved in version 5.5.7.
Affected products
- codemstory 워드프레스 결제 심플페이 (pgall-for-woocommerce) <= 5.5.6
Timeline
- 2026-06-15: disclosed: Reported by qdtad to Patchstack
- 2026-06-23: advisory: Patchstack published advisory
- 2026-06-26: patched: NVD publication date and patch availability confirmed in version 5.5.7