CVE-2026-90923: Unknown Autopay

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

Affected products

  • Unknown Autopay: before 5.0.1 (fixed in 5.0.1)

Published 2026-09-17. Last modified 2026-09-18.