PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14293 Autopay CVE debrief

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.

Vendor
Autopay
Product
Autopay WordPress plugin
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-26
Advisory published
2026-08-10
Advisory updated
2026-08-26

Who should care

Administrators and users with access to the checkout page of WordPress sites using the Autopay plugin should verify the plugin version and update to 5.0.1 or later. They should also monitor for suspicious JavaScript execution and review plugin configuration and user roles. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organizations. They should review the plugin configuration and user roles to ensure that the plugin is properly configured and that user roles are limited to only those who need access to the checkout page. Furthermore, operators of WordPress sites using the Autopay plugin should be aware of this vulnerability and its potential impact on their sites. They should review the plugin configuration and user roles to ensure that the plugin is properly configured and that user roles are limited to only those who need access to the checkout page. This vulnerability could potentially allow unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page, which could lead to unauthorized actions or data breaches. Therefore, it is essential for administrators and users with access to the checkout page to take immediate action to mitigate this vulnerability. This includes verifying the plugin version and updating to 5.0.1 or later, monitoring for suspicious JavaScript execution, and reviewing plugin configuration and user roles. By taking these steps, administrators and users can help prevent potential attacks and protect their WordPress sites from exploitation. The vulnerability management team should also consider implementing additional security measures, such as compensating controls, to further mitigate the risk of this vulnerability. This could include implementing web application firewalls or intrusion detection systems to detect and prevent potential attacks. Additionally, the security team should review the plugin configuration and user roles to ensure that the plugin is properly configured and that user roles are limited to only those who need access to the checkout page. By taking a (

Technical summary

The Autopay WordPress plugin before 5.0.1 is vulnerable to unauthenticated JavaScript injection. Attackers can store malicious JavaScript code that executes in the browser of any user, including administrators, who loads the checkout page. This is possible because the plugin does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page. The vulnerability affects WordPress sites using the Autopay plugin. Administrators and users with access to the checkout page should verify the plugin version and update to 5.0.1 or later.

Defensive priority

Administrators and users with access to the checkout page should verify the Autopay plugin version and update to 5.0.1 or later. Monitor for suspicious JavaScript execution.

Recommended defensive actions

  • Update Autopay plugin to version 5.0.1 or later
  • Monitor for suspicious JavaScript execution
  • Verify plugin configuration and user roles
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page. This could allow unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page. Defenders should verify the plugin version and update to 5.0.1 or later. They should also monitor for suspicious JavaScript execution and review plugin configuration and user roles.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14293 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14293

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14293 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14293

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.