Vulnerabilities and security researches forwp-easy-pay wp-easy-pay
Direction: ascendingJun 07, 2024
WP EasyPay – Square for WordPress # 206aa8b706721ec996e1673c01a3d16da642fd74
- CVE, Research URL
- Application
- Date
- Feb 28, 2022
- Research Description
- WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 4.0.2 WordPress WP EasyPay plugin < 4.0.2 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress WP EasyPay plugin (versions < 4.0.2).
- Affected versions
-
max 4.0.2.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # CVE-2022-47177
- CVE, Research URL
- Application
- Date
- May 25, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions.
- Affected versions
-
max 4.1.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # CVE-2021-4411
- CVE, Research URL
- Application
- Date
- Jul 12, 2023
- Research Description
- The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for unauthenticated attackers to trigger a transactions download via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.2.3.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # CVE-2023-1465
- CVE, Research URL
- Application
- Date
- Aug 16, 2023
- Research Description
- The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin
- Affected versions
-
max 4.1.
- Status
-
vulnerable
Jul 25, 2024
WP EasyPay – Square for WordPress # CVE-2024-5861
- CVE, Research URL
- Application
- Date
- Jul 24, 2024
- Research Description
- The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to disconnect square.
- Affected versions
-
max 4.2.4.
- Status
-
vulnerable
Nov 15, 2024
WP EasyPay – Square for WordPress # CVE-2022-4974
- CVE, Research URL
- Application
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 4.0.2.
- Status
-
vulnerable
Mar 30, 2026
WP EasyPay – Square for WordPress # CVE-2026-32587
- CVE, Research URL
- Application
- Date
- Mar 16, 2026
- Research Description
- Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.
- Affected versions
-
max 4.2.12.
- Status
-
vulnerable
May 15, 2026
WP EasyPay – Square for WordPress # CVE-2026-45215
- CVE, Research URL
- Application
- Date
- May 12, 2026
- Research Description
- Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.
- Affected versions
-
max 4.4.0.
- Status
-
vulnerable
Jun 16, 2026
WP EasyPay – Square for WordPress # e03420c55099714ac90da016761d318e5e1cb6db
- CVE, Research URL
- Application
- Date
- -
- Research Description
- WP Easy Pay – Payment and Donation Form Builder for Square [wp-easy-pay] < 3.2.3 404 Page Not Found
- Affected versions
-
max 3.2.3.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # dc3128cc28636dcc2da974ce09fd999dc98f52e2
- CVE, Research URL
- Application
- Date
- Feb 28, 2022
- Research Description
- WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 4.0.2 WordPress WP EasyPay plugin < 4.0.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress WP EasyPay plugin (versions < 4.0.2).
- Affected versions
-
max 4.0.2.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # 1c39044e5e76f9b4c8a3030ca01701e794c5a66c
- CVE, Research URL
- Application
- Date
- Jul 05, 2021
- Research Description
- WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 3.2.3 WordPress WP EasyPay plugin <= 3.2.0 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress WP EasyPay plugin (versions <= 3.2.0).
- Affected versions
-
max 3.2.3.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # 20851a18-8309-4405-b85c-acaa047effa7
- CVE, Research URL
- Application
- Date
- -
- Research Description
- WP Easy Pay – Payment and Donation Form Builder for Square [wp-easy-pay] < 3.2.1 CSRF Bypass in Multiple Plugins Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions
- Affected versions
-
max 3.2.1.
- Status
-
vulnerable
WP EasyPay – Square for WordPress # 6d8910c719b2a132ec93828cd37e418b19cac960
- CVE, Research URL
- Application
- Date
- Mar 04, 2022
- Research Description
- WP Easy Pay – Payment and Donation form Builder for Square [wp-easy-pay] < 4.0.2 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 4.0.2.
- Status
-
vulnerable
Jun 20, 2026
WP EasyPay – Square for WordPress # CVE-2026-56024
- CVE, Research URL
- Application
- Date
- Jun 18, 2026
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.
- Affected versions
-
max 4.4.0.
- Status
-
vulnerable
Jul 13, 2026
WP EasyPay – Square for WordPress # CVE-2026-12738
- CVE, Research URL
- Application
- Date
- Jul 11, 2026
- Research Description
- The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.
- Affected versions
-
max 4.5.1.
- Status
-
vulnerable
Jul 31, 2026
WP EasyPay – Square for WordPress # CVE-2026-57808
- CVE, Research URL
- Application
- Date
- Jul 23, 2026
- Research Description
- Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
- Affected versions
-
max 4.5.1.
- Status
-
vulnerable
Sep 04, 2026
WP EasyPay – Square for WordPress # CVE-2026-84762
- CVE, Research URL
- Application
- Date
- Sep 03, 2026
- Research Description
- Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
- Affected versions
-
max 4.5.4.
- Status
-
vulnerable