← WordPress Vulnerabilities
WordPress security by component

Simple Payment

Simple Payment (simple-payment) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.

Plugin slug: simple-payment

CVE-2026-62111: Simple Payment permits contributor cross-site scripting

Simple Payment through 2.5.4 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.

PublishedSep 11, 2026
Known safe version2.5.6
Published vulnerabilities for simple-payment
Safe version
Sep 11, 2026 CVE-2026-62111
Simple Payment permits contributor cross-site scripting
Simple Payment through 2.5.4 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
2.5.6
CVE6.5
NVDPending
Sep 03, 2026 CVE-2026-81292
Simple Payment permits unauthenticated cross-site scripting
Simple Payment through 2.5.1 allows unauthenticated attacker-controlled input to reach browser output without adequate neutralization. A victim who interacts with the affected payment output can execute script in the site's origin.
2.5.2
CVE7.1
NVDPending
Aug 28, 2026 CVE-2026-81767
Simple Payment exposes a high-integrity operation without authentication
Simple Payment through 2.5.2 does not enforce authorization on an operation reachable without a WordPress account. An unauthenticated attacker can invoke that operation and make a high-impact change to protected payment or plugin state.
2.5.3
CVE7.5
NVDPending
Nov 06, 2025 CVE-2025-62076
Simple Payment: Cross-site scripting
Simple Payment is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Nov 06, 2025 CVE-2025-62075
Simple Payment: Code execution
Simple Payment is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVDPending
Jun 27, 2025 CVE-2025-6688
Simple Payment: Privilege escalation or authentication bypass
Simple Payment is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Dec 13, 2024 CVE-2024-54303
Simple Payment: Cross-site scripting
Simple Payment is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending