PatchSiren cyber security CVE debrief
CVE-2026-90923 Autopay CVE debrief
The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders. This vulnerability affects WordPress installations with the Autopay plugin, potentially leading to disclosure and deletion of sensitive payment information. Defenders should assess exposure and prioritize verification and remediation efforts. The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact.
- Vendor
- Autopay
- Product
- Autopay WordPress plugin
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for WordPress installations with the Autopay plugin should assess exposure and prioritize verification and remediation.
Why it matters
Defenders should prioritize verifying the version of the Autopay WordPress plugin and ensuring it is updated to 5.0.1 or later to prevent potential disclosure and deletion of stored payment parameters.
- Potential disclosure of stored payment parameters
- Potential deletion of stored payment parameters
- Verification of plugin version and payment callback signatures
- Prioritization of remediation based on business criticality
Technical summary
The Autopay WordPress plugin before 5.0.1 is vulnerable due to a lack of signature enforcement on one of its payment callbacks. This allows unauthenticated users to access and delete stored payment parameters of other customers' orders. The vulnerability is specific to the Autopay plugin and can be mitigated by updating to version 5.0.1 or later. It is essential to review payment callback signatures to prevent unauthorized access and monitor for potential disclosure and deletion of stored payment parameters.
Defensive priority
Defenders should prioritize verifying the version of the Autopay WordPress plugin and ensuring it is updated to 5.0.1 or later.
Recommended defensive actions
- Verify the version of the Autopay WordPress plugin and update to 5.0.1 or later
- Review payment callback signatures to prevent unauthorized access
- Monitor for potential disclosure and deletion of stored payment parameters
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90923 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90923
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90923 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90923
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/29133c48-ff5c-4295-bd18-7014d7650298/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.