Executive brief
Epayco is a WordPress payment gateway plugin used by online stores to process transactions. An unauthenticated SQL injection vulnerability in versions 8.4.6 and earlier allows attackers to read, modify, or delete the entire database without requiring a login, potentially exposing customer payment data, personal information, and enabling account takeovers or website compromise.
Technical details
The vulnerability is a SQL injection flaw in the Epayco WordPress plugin (versions ≤ 8.4.6) that requires no authentication to exploit. The vulnerability allows attackers to inject arbitrary SQL commands through an unprotected endpoint or parameter, enabling database enumeration, data exfiltration, modification, or deletion. The attack is network-reachable and can be leveraged against any website running a vulnerable version of the plugin. The fix is available in version 8.4.7 and later.
Affected products
- Epayco Epayco <= 8.4.6
Timeline
- 2026-08-27: disclosed
- 2026-08-25: patched: Patch released in version 8.4.7