CVE-2026-18031 PUBLISHED

TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback

Assigner: WPScan
Reserved: 28.07.2026 Published: 19.08.2026 Updated: 19.08.2026

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.

Product Status

Vendor Unknown
Product TabaPay Gateway
Versions Default: unknown
  • affected from 0 to 1.4.0 (incl.)

Credits

  • moonge finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE