Loading market data...
← Back to CVE feed

CVE-2026-90923

MEDIUM CVSS 6.5 View on NVD ↗

Description

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Sep 17, 2026 06:16 UTC Modified: Sep 17, 2026 13:16 UTC