Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update the WordPress WP Express Checkout (Accept PayPal Payments) Plugin to the latest available version (at least 2.5.0).
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | |
| Title | WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Broken Access Control vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-09-30T13:27:12.372Z
Reserved: 2026-09-23T17:30:22.498Z
Link: CVE-2026-96818
No data.
Status : Received
Published: 2026-09-30T13:17:31.177
Modified: 2026-09-30T13:17:31.177
Link: CVE-2026-96818
No data.
OpenCVE Enrichment
No data.
Weaknesses