Executive brief
Simple Payment is a WordPress plugin used by website owners to accept payments on their sites. The plugin contains a cross-site scripting (XSS) vulnerability that allows attackers with contributor-level access to inject malicious scripts. If a privileged user visits a crafted page or clicks a malicious link, attackers can steal visitor data or hijack user accounts.
Technical details
The Simple Payment WordPress plugin version 2.5.4 and earlier contains a stored or reflected cross-site scripting (XSS) vulnerability in a contributor-accessible component. The vulnerability allows authenticated users with contributor-level privileges to inject malicious JavaScript code. Successful exploitation requires user interaction—a privileged user must click a malicious link or visit a crafted page. An attacker can steal sensitive data from site visitors or perform account hijacking. The vulnerability was patched in version 2.5.6.
Affected products
- yalla ya! Simple Payment <= 2.5.4
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Version 2.5.6 or later