PatchSiren

iPOSPays CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM iPOSPays CVE published 2026-04-08

CVE-2026-39608

A Missing Authorization vulnerability in iPOSPays iPOSpays Gateways WC allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPOSpays Gateways WC: from n/a through <= 1.3.7. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The CVE record and NVD entry provide limited information about the vulnerability, but it is clear that the vulnerabi [truncated]