Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-07-13

CVE-2026-12738 - Wp Easy Pay Plugin

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.

PLUGIN Wp Easy Pay

CVE-2026-12738

MEDIUM CVSS 4.3 2026-07-11
Threat Entry Updated 2024-11-21

CVE-2024-5861 - Wp Easy Pay Plugin

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to disconnect square.

PLUGIN Wp Easy Pay

CVE-2024-5861

MEDIUM CVSS 5.3 2024-07-24
Threat Entry Updated 2026-04-08

CVE-2021-4411 - Wp Easy Pay Plugin

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for unauthenticated attackers to trigger a transactions download via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Easy Pay

CVE-2021-4411

MEDIUM CVSS 4.3 2023-07-12
Scroll to top