Executive brief
The Simple Payment WordPress plugin is used by website administrators to process payments on their sites. An unauthenticated vulnerability allows attackers to access pages or perform actions they should not be permitted, such as viewing other users' payment data or transaction details without requiring a login or authorization. Websites using vulnerable versions are at risk of unauthorized data access and potential payment information exposure.
Technical details
The vulnerability is a broken access control flaw in the Simple Payment WordPress plugin versions 2.5.2 and earlier. The affected endpoints fail to properly enforce authorization checks, allowing unauthenticated users to directly access sensitive pages and functionality that should be restricted. The attack vector is network-based and requires no authentication or user interaction. An attacker can exploit this by sending crafted requests to unprotected endpoints to view or manipulate payment-related data. The vulnerability has been patched in version 2.5.3; affected site owners should update immediately.
Affected products
- yalla ya! Simple Payment <=2.5.2
Timeline
- 2026-08-28: disclosed: Published on NVD and Patchstack
- 2026-08-28: patched: Fix available in version 2.5.3