OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96818

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The WP Express Checkout plugin versions up to 2.4.9 are vulnerable to unauthenticated broken access control, allowing attackers to potentially exploit this weakness to gain unauthorized access to sensitive functionalities. This could lead to unauthorized transactions or data exposure, posing significant risks to e-commerce operations. Organizations using this plugin should prioritize patching or upgrading to mitigate the risk of exploitation.

CVE
CVE-2026-96818
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.