Wpeasypay develops a WordPress payment-processing plugin that operates within the WordPress ecosystem and presents a focused attack surface centered on web application security. The durable signal from disclosed vulnerabilities centers on cross-site request forgery and missing authorization controls, reflecting common weaknesses in WordPress plugin implementations where state-changing operations and access checks require careful design. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpeasypay over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47177HIGH Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions. | May 25, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-1465MEDIUM The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be | Aug 16, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-5861MEDIUM The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() funct | Jul 24, 2024 | 6.5 | 19 | NO | NO |
CVE-2021-4411MEDIUM The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect | Jul 12, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpeasypay.
Media articles that mention a CVE ID that affects a product developed by Wpeasypay — matched by CVE ID, not by vendor name.