PatchSiren cyber security CVE debrief
CVE-2026-14293 Autopay CVE debrief
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.
- Vendor
- Autopay
- Product
- Autopay WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-10
Who should care
Administrators and users with access to the checkout page of WordPress sites using the Autopay plugin should verify the plugin version and update to 5.0.1 or later. They should also monitor for suspicious JavaScript execution and review plugin configuration and user roles. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organizations. They should review the plugin configuration and user roles to ensure that the plugin is properly configured and that user roles are limited to only those who need access to the checkout page. Furthermore, operators of WordPress sites using the Autopay plugin should be aware of this vulnerability and its potential impact on their sites. They should review the plugin configuration and user roles to ensure that the plugin is properly configured and that user roles are limited to only those who need access to the checkout page. This vulnerability could potentially allow unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page, which could lead to unauthorized actions or data breaches. Therefore, it is essential for administrators and users with access to the checkout page to take immediate action to mitigate this vulnerability. This includes verifying the plugin version and updating to 5.0.1 or later, monitoring for suspicious JavaScript execution, and reviewing plugin configuration and user roles. By taking these steps, administrators and users can help prevent potential attacks and protect their WordPress sites from exploitation. The vulnerability management team should also consider implementing additional security measures, such as compensating controls, to further mitigate the risk of this vulnerability. This could include implementing web application firewalls or intrusion detection systems to detect and prevent potential attacks. Additionally, the security team should review the plugin configuration and user roles to ensure that the plugin is properly configured and that user roles are limited to only those who need access to the checkout page. By taking a (
Technical summary
The Autopay WordPress plugin before 5.0.1 is vulnerable to unauthenticated JavaScript injection. Attackers can store malicious JavaScript code that executes in the browser of any user, including administrators, who loads the checkout page. This is possible because the plugin does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page. The vulnerability affects WordPress sites using the Autopay plugin. Administrators and users with access to the checkout page should verify the plugin version and update to 5.0.1 or later.
Defensive priority
Administrators and users with access to the checkout page should verify the Autopay plugin version and update to 5.0.1 or later. Monitor for suspicious JavaScript execution.
Recommended defensive actions
- Update Autopay plugin to version 5.0.1 or later
- Monitor for suspicious JavaScript execution
- Verify plugin configuration and user roles
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page. This could allow unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page. Defenders should verify the plugin version and update to 5.0.1 or later. They should also monitor for suspicious JavaScript execution and review plugin configuration and user roles.
Official resources
-
CVE-2026-14293 CVE record
CVE.org
-
CVE-2026-14293 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:47.160Z and has not been modified since then.