CVE-2025-14829: Unknown E-Xact | Hosted Payment |
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.
Affected products
- Unknown E-Xact | Hosted Payment |: up to and including 2.0
Published 2026-01-13. Last modified 2026-06-17.