What is CVE-2026-66473?
CVE-2026-66473 is an unauthenticated Broken Access Control vulnerability found in Xendit Payment plugin versions up to and including 7.1.0. This flaw may allow unauthenticated attackers to gain unauthorized access to restricted resources. Users are advised to update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-66473, Xendit Payment plaginində (7.1.0 və aşağı versiyalar) aşkarlanmış autentifikasiya olunmamış Broken Access Control zəifliyidir. Bu zəiflik autentifikasiya olunmamış şəxslərə məhdud resurslara icazəsiz giriş imkanı verə bilər. İstifadəçilər dərhal plaginin ən son versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which plugin and versions are affected by CVE-2026-66473?
CVE-2026-66473 affects Xendit Payment plugin versions up to and including 7.1.0.
What can an unauthenticated attacker do by exploiting CVE-2026-66473?
An unauthenticated attacker can gain unauthorized access to restricted resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.