The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-19 06:17
Updated : 2026-08-26 16:30
NVD link : CVE-2026-18031
Mitre link : CVE-2026-18031
CVE.ORG link : CVE-2026-18031
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
