CVE WATCH / VULNERABILITY DETAIL
CVE-2026-87841
MEDIUMCVSS 5.3NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-104081 HIGH 8.1
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8
- CVE-2026-94065 HIGH 8.8
- CVE-2026-100730 CRITICAL 9.8
- CVE-2026-94062 HIGH 8.1
- CVE-2026-62028 MEDIUM 5.4