CyberRota Analysis
AI-GeneratedThe Autopay WordPress plugin prior to version 5.0.1 is vulnerable due to inadequate capability and nonce checks, allowing unauthenticated attackers to inject malicious JavaScript that executes in the browsers of users, including administrators, visiting the checkout page. This could lead to session hijacking, data theft, or other malicious actions. WordPress site administrators using this plugin should prioritize updating to version 5.0.1 or later to mitigate this risk.
Original NVD Description
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.