---
id: CVE-2026-90923
title: >-
  The Autopay WordPress plugin before 5.0.1 does not enforce the signature on
  one of its payment callbacks, allowing unauthenticated users to disclose and
  delete the stored payment parameters of other customers' orders.
summary: >-
  The Autopay WordPress plugin before 5.0.1 does not enforce the signature on
  one of its payment callbacks, allowing unauthenticated users to disclose and
  delete the stored payment parameters of other customers' orders.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
product: Autopay
affected:
  - Autopay < 5.0.1
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90923'
references:
  - url: 'https://wpscan.com/vulnerability/29133c48-ff5c-4295-bd18-7014d7650298/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00275
epssPercentile: 0.17749
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:11:54.214777Z'
ingestedAt: '2026-09-17T06:12:17.970Z'
---

## Overview

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
