cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-easy-pay wp-easy-pay

Direction: ascending
Jun 07, 2024

WP EasyPay – Square for WordPress # 206aa8b706721ec996e1673c01a3d16da642fd74

Date
Feb 28, 2022
Research Description
WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 4.0.2 WordPress WP EasyPay plugin < 4.0.2 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress WP EasyPay plugin (versions < 4.0.2).
Affected versions
max 4.0.2.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # CVE-2022-47177

CVE, Research URL

CVE-2022-47177

Date
May 25, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions.
Affected versions
max 4.1.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # CVE-2021-4411

CVE, Research URL

CVE-2021-4411

Date
Jul 12, 2023
Research Description
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for unauthenticated attackers to trigger a transactions download via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.2.3.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # CVE-2023-1465

CVE, Research URL

CVE-2023-1465

Date
Aug 16, 2023
Research Description
The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin
Affected versions
max 4.1.
Status
vulnerable
Jul 25, 2024

WP EasyPay &#8211; Square for WordPress # CVE-2024-5861

CVE, Research URL

CVE-2024-5861

Date
Jul 24, 2024
Research Description
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to disconnect square.
Affected versions
max 4.2.4.
Status
vulnerable
Nov 15, 2024

WP EasyPay &#8211; Square for WordPress # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 4.0.2.
Status
vulnerable
Mar 30, 2026

WP EasyPay &#8211; Square for WordPress # CVE-2026-32587

CVE, Research URL

CVE-2026-32587

Date
Mar 16, 2026
Research Description
Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.
Affected versions
max 4.2.12.
Status
vulnerable
May 15, 2026

WP EasyPay &#8211; Square for WordPress # CVE-2026-45215

CVE, Research URL

CVE-2026-45215

Date
May 12, 2026
Research Description
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.
Affected versions
max 4.4.0.
Status
vulnerable
Jun 16, 2026

WP EasyPay &#8211; Square for WordPress # e03420c55099714ac90da016761d318e5e1cb6db

Date
-
Research Description
WP Easy Pay – Payment and Donation Form Builder for Square [wp-easy-pay] < 3.2.3 404 Page Not Found
Affected versions
max 3.2.3.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # dc3128cc28636dcc2da974ce09fd999dc98f52e2

Date
Feb 28, 2022
Research Description
WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 4.0.2 WordPress WP EasyPay plugin < 4.0.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress WP EasyPay plugin (versions < 4.0.2).
Affected versions
max 4.0.2.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # 1c39044e5e76f9b4c8a3030ca01701e794c5a66c

Date
Jul 05, 2021
Research Description
WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 3.2.3 WordPress WP EasyPay plugin <= 3.2.0 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress WP EasyPay plugin (versions <= 3.2.0).
Affected versions
max 3.2.3.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # 20851a18-8309-4405-b85c-acaa047effa7

Date
-
Research Description
WP Easy Pay – Payment and Donation Form Builder for Square [wp-easy-pay] < 3.2.1 CSRF Bypass in Multiple Plugins Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions
Affected versions
max 3.2.1.
Status
vulnerable

WP EasyPay &#8211; Square for WordPress # 6d8910c719b2a132ec93828cd37e418b19cac960

Date
Mar 04, 2022
Research Description
WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 4.0.2 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 4.0.2.
Status
vulnerable
Jun 20, 2026

WP EasyPay &#8211; Square for WordPress # CVE-2026-56024

CVE, Research URL

CVE-2026-56024

Date
Jun 18, 2026
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.
Affected versions
max 4.4.0.
Status
vulnerable
Jul 13, 2026

WP EasyPay &#8211; Square for WordPress # CVE-2026-12738

CVE, Research URL

CVE-2026-12738

Date
Jul 11, 2026
Research Description
The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.
Affected versions
max 4.5.1.
Status
vulnerable
Jul 31, 2026

WP EasyPay &#8211; Square for WordPress # CVE-2026-57808

CVE, Research URL

CVE-2026-57808

Date
Jul 23, 2026
Research Description
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Affected versions
max 4.5.1.
Status
vulnerable
Sep 04, 2026

WP EasyPay &#8211; Square for WordPress # CVE-2026-84762

CVE, Research URL

CVE-2026-84762

Date
Sep 03, 2026
Research Description
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
Affected versions
max 4.5.4.
Status
vulnerable