Security Advisory

CVE-2026-18031

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 06:00:18
Last updated 2026-08-19 17:10:10
Assigner WPScan
CVSS score 9.8
State PUBLISHED

Description

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.