Executive brief
Frisbii Pay is a WordPress plugin used to process payments and manage checkout gateways. A security flaw in versions 1.8.2 and earlier allows users with low-level 'Contributor' permissions to elevate their privileges to a higher level, such as Administrator. This could allow an internal user or an attacker who has gained basic access to take full control of the website, potentially leading to data theft or service disruption.
Technical details
A privilege escalation vulnerability exists in the Frisbii Pay plugin (formerly Reepay Checkout Gateway) for WordPress in versions up to 1.8.2. The flaw allows an authenticated attacker with Contributor-level roles or higher to escalate their privileges, potentially gaining full administrative control over the WordPress site. The vulnerability likely stems from insufficient permission checks on sensitive functions or settings updates. An attacker can exploit this over the network without user interaction. Users are advised to update to the latest version where a fix is available.
Affected products
- Frisbii Pay Frisbii Pay <= 1.8.2
Timeline
- 2026-06-26: advisory: Vulnerability published to NVD