All 3 CVE vulnerabilities found in WP Easy Pay – Payment and Donation form Builder for Square, with AI-generated Chinese analysis, references, and POCs.
Vendor: saadiqbal
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-12738 | WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action CWE-862 | 4.3 | Medium | 2026-07-11 |
| CVE-2024-5861 | WP Easy Pay (Free) <= 4.2.3 - Missing Authorization to Unauthenticated Service Disconnection CWE-862 | 5.3 | Medium | 2024-07-24 |
| CVE-2021-4411 | WP EasyPay – Square for WordPress <= 3.2.0 - Cross-Site Request Forgery Bypass CWE-352 | 4.3 | Medium | 2023-07-12 |
All 3 known CVE vulnerabilities affecting WP Easy Pay – Payment and Donation form Builder for Square with full Chinese analysis, references, and POCs where available.