CVE-2026-14293
Received Received - Intake

Stored Cross-Site Scripting in Autopay WordPress Plugin

Vulnerability report for CVE-2026-14293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user, including administrators, who loads the checkout page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
autopay autopay to 5.0.1 (exc)
blue_media autopay to 5.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Autopay WordPress plugin before version 5.0.1 has a stored cross-site scripting (XSS) vulnerability. It allows unauthenticated attackers to inject malicious JavaScript by exploiting missing capability and nonce checks when saving styling options. This injected script executes in the browsers of any user, including administrators, who visit the checkout page.

Detection Guidance

Check if the Autopay WordPress plugin version is below 5.0.1 by inspecting the plugin files or WordPress admin panel. Look for unauthorized JavaScript in the CSS Editor settings or checkout page output.

Impact Analysis

This vulnerability allows attackers to steal sensitive user data like session cookies or login credentials by executing malicious scripts in the browser of anyone visiting the checkout page. It could also enable attackers to perform actions on behalf of users or administrators without their consent.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by exposing user data through unauthorized script execution. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update the Autopay plugin to version 5.0.1 or later immediately. Remove any suspicious JavaScript from the CSS Editor settings and review checkout page output for unauthorized code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart