Sceawere
Vulnerability Detail
CVE-2026-96818UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Broken Access Control Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- mra13 / Team Tips and…
- Product
- WP Express Checkout (Accept PayPal Payments)
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T13:17:31.177Z",
"pubdate": "2026-09-30T13:17:31.177Z",
"executiveSummary": "The WP Express Checkout (Accept PayPal Payments) plugin, versions 2.4.9 and earlier, is susceptible to an unauthenticated broken access control vulnerability. This security flaw allows unauthenticated remote attackers to bypass authorization mechanisms, potentially leading to unauthorized modification of plugin configurations or data manipulation. The vulnerability stems from improper validation of access control checks within the plugin's request handling logic. Exploitation does not require prior authentication or elevated privileges, making it accessible to any external attacker capable of reaching the target WordPress installation. The risk implication is significant, as it exposes the plugin settings to unauthorized influence, potentially compromising the integrity of payment processes or plugin operational security. Organizations utilizing affected versions are at risk of malicious actors leveraging this gap to perform actions intended only for administrative users.",
"technicalDetails": "The root cause of the vulnerability lies in the insufficient enforcement of authentication and authorization checks within the request handling routines of the WP Express Checkout plugin. Specifically, the affected code paths fail to verify that the user initiating a request possesses the requisite administrative capabilities before executing sensitive functional logic.\nUnder normal operating conditions, sensitive plugin actions—such as updating settings, modifying payment configurations, or interacting with sensitive internal data—should be wrapped in security checks utilizing WordPress native functions like 'current_user_can()'. In affected versions 2.4.9 and lower, these checks are either missing, improperly implemented, or bypassed, allowing any unauthenticated remote request to trigger backend functions that modify plugin state.\nThe attack flow commences with an attacker identifying a vulnerable entry point, typically through crafted HTTP GET or POST requests directed at specific plugin-registered endpoints or administrative actions exposed to the frontend. Because the application logic lacks proper nonce verification and capability checks, the attacker can submit malicious payloads directly to these handlers.\nWhen a request is received, the plugin fails to perform a session or capability validation. Consequently, the application processes the request as if it originated from an authorized administrator. This allows the attacker to interact with the plugin's internal API to alter configurations or perform other state-changing operations. The exposure is total regarding the plugin's administrative functionality; any action normally performable by an administrator can be executed via this unauthorized channel.\nThe lack of authentication requirements means that network exposure is high, as the vulnerability is reachable over the web via standard HTTP/HTTPS traffic. Exploitation does not require local file access or elevated server permissions; the impact is strictly confined to the scope of the plugin's influence on the WordPress environment. Post-exploitation, an attacker can manipulate payment settings, modify transaction handling logic, or potentially cause denial-of-service conditions by altering critical plugin parameters to invalid states. Given that this plugin facilitates financial transactions via PayPal, unauthorized configuration changes could lead to direct monetary redirection or the disruption of critical business revenue streams."
}