CRITICAL 9.8 CVE-2026-18031 Published 19 Aug 2026

WordPress TabaPay Gateway Plugin Unauthenticated Admin Login

Worried this affects your website?

The TabaPay Gateway WordPress plugin, up to version 1.4.0, has a vulnerability that allows unauthenticated attackers to log in as any registered user, including an administrator.

This is due to the plugin not validating the payment callback before establishing a session for the associated account.

Reference: CVE-2026-18031 on NVD

← Back to Security News