AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66461

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in SMEPay's UPI Gateway for WooCommerce versions up to 1.0.5 allows unauthenticated users to exploit broken access control, potentially leading to unauthorized actions within the application. This could result in significant data exposure or manipulation, impacting the integrity of transactions. E-commerce platforms utilizing this plugin should prioritize remediation to safeguard against potential exploitation.

CVE
CVE-2026-66461
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.