CVE-2026-87841: Unknown Unitechpay

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.

Affected products

  • Unknown Unitechpay: up to and including 1.0.6.3

Published 2026-10-09. Last modified 2026-10-09.