OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-39751

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

PayPlug for WooCommerce versions up to 3.1.0 are vulnerable to unauthenticated broken access control, allowing attackers to gain unauthorized access to sensitive functionalities. This flaw could lead to unauthorized transactions or data exposure, posing a significant risk to e-commerce operations. Merchants using affected versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-39751
Severity
HIGH
CVSS
7.5
EPSS
N/A

Original NVD Description

Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.