Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-90923 2 Autopay, Wordpress 2 Autopay, Wordpress 2026-09-18 6.5 Medium
The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.
CVE-2026-73338 2 Autopay, Wordpress 2 Autopay, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.