cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forelegro-payment elegro-payment

Direction: ascending
Oct 08, 2026

elegro Crypto Payment # CVE-2026-94299

CVE, Research URL

CVE-2026-94299

Application

elegro Crypto Payment

Date
Oct 06, 2026
Research Description
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value.
Affected versions
max 1.0.1.
Status
vulnerable