Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-18031: TabaPay Gateway <= 1.4.0: Unauthenticated Account Takeover via Payment

CVE-2026-18031 · published 1 month ago
Summary

The TabaPay Gateway WordPress plugin is vulnerable to an account takeover attack. Attackers can log in as any registered user, including administrators, without needing a password. Update the plugin to a version greater than 1.4.0 to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown tabapay gateway <= 1.4.0
Original advisory text
TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published19 Aug 2026
Updated27 Sep 2026
First seen19 Aug 2026
Sources
CVE-2026-18031 · MITRE
Track software like this
Free during beta