Junglewise Threat Intelligence

CVE-2026-81292: Simple Payment plugin unauthenticated cross-site scripting

CVE-2026-81292 · Severity: high · CVSS 7.1 · Published 2026-09-03

Technologies: Yalla Ya! Simple Payment. Vendors: Yalla Ya!.

Executive brief

The Simple Payment WordPress plugin contains a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious scripts into affected websites. An attacker can craft a malicious link or page that, when visited by an administrator or user, executes arbitrary JavaScript code that could steal account credentials, session tokens, or perform unauthorized actions on the site.

Technical details

This is an unauthenticated reflected or stored cross-site scripting (XSS) vulnerability in the Simple Payment WordPress plugin version 2.5.1 and earlier. The vulnerability allows attackers to inject arbitrary HTML and JavaScript payloads into the plugin's output without proper input validation or output encoding. While user interaction is required (an administrator or privileged user must click a malicious link or visit a crafted page), no authentication is needed to create the payload. Successful exploitation enables attackers to steal sensitive data, hijack user sessions, or perform actions with the privileges of the victim user. The vulnerability has been patched in version 2.5.2.

Affected products

  • yalla ya! Simple Payment <=2.5.1

Timeline

  • 2026-09-03: disclosed: CVE-2026-81292 published
  • 2026-09-02: patched: Version 2.5.2 released

References

Related threats