SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18031

CRITICAL · CVSS 9.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The TabaPay Gateway plugin for WordPress versions up to 1.4.0 is vulnerable due to inadequate validation of payment callbacks, enabling unauthenticated attackers to gain access to any registered user account, including those with administrative privileges. This flaw poses a significant security risk as it could lead to unauthorized access and potential manipulation of user data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-18031
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%
WordPress

Original NVD Description

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.