PatchSiren

Wava.co CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Wava.co CVE published 2026-04-08

CVE-2026-39609

A Missing Authorization vulnerability exists in Wava Payment, affecting versions from n/a through 0.3.7. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability arises from incorrectly configured access control security levels in the Wava Payment plugin, potentially allowing unauthorized actions. Users and [truncated]