Junglewise Threat Intelligence

CVE-2026-61954: PayU India WordPress plugin broken access control

CVE-2026-61954 · Severity: high · CVSS 7.5 · Published 2026-07-23

Executive brief

The PayU India plugin for WordPress, which facilitates payment processing, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could exploit this to bypass security checks and potentially interfere with payment-related functions or site integrity. This could lead to unauthorized modifications of site data or disruptions in the payment workflow.

Technical details

A broken access control vulnerability exists in the PayU India WordPress plugin due to missing authorization checks (CWE-862) in versions up to and including 3.8.9. The flaw allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. According to the CVSS vector, the primary impact is on integrity, suggesting that an attacker can modify data or settings without proper authentication. The issue is resolved in version 3.9.0.

Affected products

  • PayU India PayU India <= 3.8.9

Timeline

  • 2026-06-10: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: advisory: NVD published CVE-2026-61954
  • 2026-07-23: patched: Version 3.9.0 identified as unaffected

References