Junglewise Threat Intelligence

CVE-2026-66473: Xendit Payment broken access control in WordPress plugin

CVE-2026-66473 · Severity: high · CVSS 7.5 · Published 2026-07-27

Executive brief

Xendit Payment is a WordPress plugin used by online stores to process payments and manage virtual accounts. A security flaw allows unauthorized individuals to bypass access controls, potentially allowing them to interfere with payment processes or modify transaction data. This could lead to financial discrepancies or operational disruptions for e-commerce businesses using the plugin.

Technical details

A broken access control vulnerability (CWE-862) exists in the Xendit Payment plugin (woo-xendit-virtual-accounts) for WordPress in versions up to and including 7.1.0. The flaw stems from missing authorization checks on a specific endpoint, allowing an unauthenticated remote attacker to execute functions that should be restricted to privileged users. According to the advisory, the vulnerability is significant enough that third-party security providers have implemented rules to block all requests to the affected endpoint. As of the reporting date, no official patch from the vendor has been confirmed.

Affected products

  • Xendit Xendit Payment (woo-xendit-virtual-accounts) <= 7.1.0

Timeline

  • 2026-05-18: disclosed: Reported by security researcher Mitchell
  • 2026-07-27: advisory: Published by Patchstack and NVD

References