PT-2026-33018 · WordPress · Visa Acceptance Solutions

Jude Nwadinobi

·

Published

2026-04-15

·

Updated

2026-04-24

·

CVE-2026-3461

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Visa Acceptance Solutions versions prior to 2.1.1
Description The Visa Acceptance Solutions plugin for WordPress allows unauthenticated attackers to log in as any existing user, including administrators. This occurs because the express pay product page pay for order() function logs users in based solely on a user-supplied billing email address during guest checkout for subscription products, without verifying email ownership, requiring a password, or validating a one-time token. An attacker can achieve complete account takeover and site compromise by providing the target user's email address in the billing details parameter.
Recommendations Update the plugin to a version later than 2.1.0.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-3461

Affected Products

Visa Acceptance Solutions