CVE-2026-87841
UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.
| Vendor | unknown |
| Product | unitechpay |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown unitechpay
Be the first to know when new unknown vulnerabilities affecting unknown unitechpay are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / UnitechPay
0 โค 1.0.6.3
References
Credits
Timur WPScan