Junglewise Threat Intelligence

CVE-2026-84762: WP EasyPay authentication bypass

CVE-2026-84762 · Severity: medium · CVSS 5.3 · Published 2026-09-03

Executive brief

WP EasyPay is a WordPress plugin that handles payment processing on websites. This vulnerability allows unauthenticated attackers to bypass security checks, potentially gaining unauthorized access to payment functions or sensitive data without proper authentication.

Technical details

This vulnerability is a bypass vulnerability in WP EasyPay plugin that allows unauthenticated attackers to circumvent security checks without valid credentials. The issue is classified as an insecure design flaw (OWASP A4) and requires no special privilege to exploit. Attackers can leverage this flaw to bypass authentication controls and potentially access payment processing functions or other protected features. The vulnerability was patched in version 4.5.4, and administrators should update immediately to mitigate the risk.

Affected products

  • WPExperts WP EasyPay 4.5.3 and earlier

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Version 4.5.4 released

References