AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14293

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Autopay WordPress plugin prior to version 5.0.1 is vulnerable due to inadequate capability and nonce checks, allowing unauthenticated attackers to inject malicious JavaScript that executes in the browsers of users, including administrators, visiting the checkout page. This could lead to session hijacking, data theft, or other malicious actions. WordPress site administrators using this plugin should prioritize updating to version 5.0.1 or later to mitigate this risk.

CVE
CVE-2026-14293
Severity
HIGH
CVSS
8.8
EPSS
0.28%
WordPress Java

Original NVD Description

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.