PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90923 Autopay CVE debrief

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders. This vulnerability affects WordPress installations with the Autopay plugin, potentially leading to disclosure and deletion of sensitive payment information. Defenders should assess exposure and prioritize verification and remediation efforts. The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact.

Vendor
Autopay
Product
Autopay WordPress plugin
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress installations with the Autopay plugin should assess exposure and prioritize verification and remediation.

Why it matters

Defenders should prioritize verifying the version of the Autopay WordPress plugin and ensuring it is updated to 5.0.1 or later to prevent potential disclosure and deletion of stored payment parameters.

  • Potential disclosure of stored payment parameters
  • Potential deletion of stored payment parameters
  • Verification of plugin version and payment callback signatures
  • Prioritization of remediation based on business criticality

Technical summary

The Autopay WordPress plugin before 5.0.1 is vulnerable due to a lack of signature enforcement on one of its payment callbacks. This allows unauthenticated users to access and delete stored payment parameters of other customers' orders. The vulnerability is specific to the Autopay plugin and can be mitigated by updating to version 5.0.1 or later. It is essential to review payment callback signatures to prevent unauthorized access and monitor for potential disclosure and deletion of stored payment parameters.

Defensive priority

Defenders should prioritize verifying the version of the Autopay WordPress plugin and ensuring it is updated to 5.0.1 or later.

Recommended defensive actions

  • Verify the version of the Autopay WordPress plugin and update to 5.0.1 or later
  • Review payment callback signatures to prevent unauthorized access
  • Monitor for potential disclosure and deletion of stored payment parameters

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90923 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90923

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90923 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90923

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.