← Terug naar overzicht

A critical unauthenticated SQL injection vulnerability has been identified in the Epayco WordPress plugin versions 8.4.6 and below. The flaw allows unauthenticated attackers to interact directly with the database, potentially exposing sensitive data or enabling full database compromise. No authentication is required to exploit this vulnerability, making it particularly dangerous in production environments. The vulnerability is tracked under CVE-2026-78260 and has been documented by both the NVD and Patchstack. Users of the Epayco payment gateway plugin for WordPress are advised to update to a patched version immediately. SQL injection vulnerabilities of this nature can lead to data exfiltration, authentication bypass, and in some cases remote code execution depending on server configuration.

Affected products

  • Epayco WordPress Plugin <= 8.4.6

Related CVE's

  • CVE-2026-78260

Categories

  • Database & Storage
  • Web Technologies