CVE-2026-87841 PUBLISHED

UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook

Assigner: WPScan
Reserved: 09.09.2026 Published: 09.10.2026 Updated: 09.10.2026

The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.

Product Status

Vendor Unknown
Product UnitechPay
Versions Default: unknown
  • affected from 0 to 1.0.6.3 (incl.)

Credits

  • Timur finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE