WordPress security by component
Simple Payment
Simple Payment (simple-payment) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
simple-paymentLatest vulnerability
CVE-2026-62111: Simple Payment permits contributor cross-site scripting
Simple Payment through 2.5.4 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62111
Simple Payment permits contributor cross-site scripting
Simple Payment through 2.5.4 permits cross-site scripting by an authenticated Contributor. The CNA vector requires another user to interact with the affected content and rates confidentiality, integrity, and availability impacts as low. The authoritative export does not identify the endpoint, action, parameter, storage path, rendering function, or output context.
|
2.5.6 |
CVE6.5
NVDPending
|
| Sep 03, 2026 |
CVE-2026-81292
Simple Payment permits unauthenticated cross-site scripting
Simple Payment through 2.5.1 allows unauthenticated attacker-controlled input to reach browser output without adequate neutralization. A victim who interacts with the affected payment output can execute script in the site's origin.
|
2.5.2 |
CVE7.1
NVDPending
|
| Aug 28, 2026 |
CVE-2026-81767
Simple Payment exposes a high-integrity operation without authentication
Simple Payment through 2.5.2 does not enforce authorization on an operation reachable without a WordPress account. An unauthenticated attacker can invoke that operation and make a high-impact change to protected payment or plugin state.
|
2.5.3 |
CVE7.5
NVDPending
|
| Nov 06, 2025 |
CVE-2025-62076
Simple Payment: Cross-site scripting
Simple Payment is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Nov 06, 2025 |
CVE-2025-62075
Simple Payment: Code execution
Simple Payment is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 27, 2025 |
CVE-2025-6688
Simple Payment: Privilege escalation or authentication bypass
Simple Payment is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Dec 13, 2024 |
CVE-2024-54303
Simple Payment: Cross-site scripting
Simple Payment is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|