๐Ÿ” CVE Alert

CVE-2026-18031

UNKNOWN 0.0

TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.

Vendor unknown
Product tabapay gateway
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown tabapay gateway

Be the first to know when new unknown vulnerabilities affecting unknown tabapay gateway are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / TabaPay Gateway
0 โ‰ค 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6576dcd1-aea6-47c0-9157-4ca56f426612/

Credits

moonge WPScan