What is CVE-2026-14293?
The Autopay WordPress plugin before version 5.0.1 lacks capability and nonce checks when saving styling options from public requests. This allows unauthenticated attackers to execute stored JavaScript on the checkout page. Updating the plugin to at least version 5.0.1 is recommended.
Azərbaycanca: Autopay WordPress plaqini 5.0.1 versiyasından əvvəlki versiyalarda `nonce` və icazə yoxlaması olmadan ictimai sorğudan stil seçimini saxlayır. Bu, autentifikasiya olunmamış hücumçuya ödəniş səhifəsində saxlanılan JavaScript-in işə düşməsinə imkan verir. Plaqini ən azı 5.0.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What is the nature of the CVE-2026-14293 vulnerability in the Autopay WordPress plugin?
In versions before 5.0.1, the plugin lacks capability and nonce checks when saving styling options, allowing unauthenticated attackers to execute stored JavaScript on the checkout page.
How can the CVE-2026-14293 vulnerability be mitigated?
It is recommended to update the Autopay plugin to at least version 5.0.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.