Ciberseguridadlatam
WordPress Plugin Vulnerabilities Expose Online Stores and Multisite Networks
Article Content
Two vulnerabilities affecting WordPress plugins have been disclosed, impacting online stores and multisite networks. CVE-2026-81423 allows attackers to redirect visitors from online stores using the Accept Stripe Payments plugin to phishing sites without authentication. This flaw affects all versions prior to 2.1.4 and is due to inadequate URL validation. Meanwhile, CVE-2026-83628 in the Theme My Login plugin enables authenticated users to create unauthorized subsites in Multisite networks, affecting all versions up to 7.1.15. Both vulnerabilities were published on September 5, 2026, and are classified as medium severity by NIST. The impact is significant, particularly in regions like Latin America, where many businesses rely on these plugins for e-commerce and centralized site management. Merchants and educational institutions using these plugins are at risk of data breaches and unauthorized access.
Key Points: • CVE-2026-81423 allows phishing via unvalidated redirects in Accept Stripe Payments. • CVE-2026-83628 enables unauthorized subsite creation in WordPress Multisite networks. • Both vulnerabilities are classified as medium severity and were disclosed on September 5, 2026.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.