PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12739 saadiqbal CVE debrief

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary posts, pages, and custom post types (bypassing the trash via force deletion) or change any published post to draft status.

Vendor
saadiqbal
Product
WP Easy Pay – Payment and Donation Form Builder for Square
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-09-18
Advisory published
2026-09-18
Advisory updated
2026-09-18

Who should care

Defenders of WordPress installations using the WP Easy Pay plugin, especially those with subscriber-level access or above, should assess exposure and prioritize remediation. They need to verify if their WP Easy Pay plugin versions are vulnerable and update to the latest available. Restricting access to sensitive WordPress functionality for users with subscriber-level access can mitigate the vulnerability. Monitoring for suspicious activity related to post

Why it matters

CVE-2026-12739 is a medium-severity vulnerability in the WP Easy Pay plugin for WordPress, allowing authorized users to delete or modify posts. Defenders should verify exposure, restrict access, and monitor activity.

  • Defenders need to verify if their WP Easy Pay plugin versions are vulnerable and update to the latest available.
  • Restricting access to sensitive WordPress functionality for users with subscriber-level access can mitigate the vulnerability.
  • Monitoring for suspicious activity related to post deletions or status changes is necessary.

Technical summary

The WP Easy Pay plugin for WordPress does not properly verify user authorization, allowing authenticated attackers with subscriber-level access to delete arbitrary posts, pages, and custom post types or change published posts to draft status. This vulnerability affects defenders of WordPress installations using the WP Easy Pay plugin, especially those with subscriber-level access or above, who should assess exposure and prioritize remediation. The vulnerability has a medium severity and requires verification of exposure, restriction of access, and monitoring of activity.

Defensive priority

Medium priority for defenders of WordPress installations using the WP Easy Pay plugin, especially those with subscriber-level access or above.

Recommended defensive actions

  • Review and update WP Easy Pay plugin versions to the latest available.
  • Restrict access to sensitive WordPress functionality for users with subscriber-level access.
  • Monitor for suspicious activity related to post deletions or status changes.
  • Confirm whether affected WP Easy Pay plugin deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. However, the corpus does not establish versions beyond 4.5.0, exploitation, impact, or remediation, which require verification from the supplied official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12739 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12739

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12739 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12739

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.