CRITICAL
9.8 CVE-2026-18031 Published 19 Aug 2026
WordPress TabaPay Gateway Plugin Unauthenticated Admin Login
Worried this affects your website?
The TabaPay Gateway WordPress plugin, up to version 1.4.0, has a vulnerability that allows unauthenticated attackers to log in as any registered user, including an administrator.
This is due to the plugin not validating the payment callback before establishing a session for the associated account.
Reference: CVE-2026-18031 on NVD
← Back to Security News