{"api_version":"1","generated_at":"2026-09-17T07:51:44+00:00","cve":"CVE-2026-90923","urls":{"html":"https://cve.report/CVE-2026-90923","api":"https://cve.report/api/cve/CVE-2026-90923.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90923","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90923"},"summary":{"title":"Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion","description":"The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-17 06:16:52","updated_at":"2026-09-17 06:16:52"},"problem_types":["CWE-863 Incorrect Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/29133c48-ff5c-4295-bd18-7014d7650298/","name":"https://wpscan.com/vulnerability/29133c48-ff5c-4295-bd18-7014d7650298/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90923","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90923","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Autopay","version":"affected 5.0.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Artus KG","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Autopay","vendor":"Unknown","versions":[{"lessThan":"5.0.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Artus KG"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders."}],"problemTypes":[{"descriptions":[{"description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-17T06:00:12.519Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/29133c48-ff5c-4295-bd18-7014d7650298/"}],"source":{"discovery":"EXTERNAL"},"title":"Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-90923","datePublished":"2026-09-17T06:00:12.519Z","dateReserved":"2026-09-14T11:12:21.172Z","dateUpdated":"2026-09-17T06:00:12.519Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 06:16:52","lastModifiedDate":"2026-09-17 06:16:52","problem_types":["CWE-863 Incorrect Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90923","Ordinal":"1","Title":"Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment P","CVE":"CVE-2026-90923","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90923","Ordinal":"1","NoteData":"The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.","Type":"Description","Title":"Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment P"}]}}}