Executive brief
WP EasyPay is a WordPress plugin used to facilitate payments and donations on websites. A security flaw in versions up to 4.5.0 allows users with basic 'Subscriber' accounts to delete website content, such as posts, pages, or images, without authorization. This could lead to significant data loss and disruption of website operations.
Technical details
The WP EasyPay plugin for WordPress is vulnerable to arbitrary content deletion due to missing authorization checks (CWE-862) in versions up to and including 4.5.0. An authenticated attacker with Subscriber-level privileges can exploit this vulnerability via a network request to delete arbitrary posts, pages, or media files. The issue stems from a failure to validate that the user requesting a deletion has the appropriate administrative permissions. This vulnerability was patched in version 4.5.1.
Affected products
- Saad Iqbal WP EasyPay <= 4.5.0
Timeline
- 2026-05-17: disclosed: Reported by researcher dodoh4t
- 2026-07-21: advisory: Patchstack advisory published
- 2026-07-23: patched: Version 4.5.1 released to address the issue