CVE-2026-4663 Details
Description
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39608. Reason: This candidate is a reservation duplicate of CVE-2026-39608. Notes: All CVE users should reference CVE-2026-39608 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
A vulnerability exists in the iPOSpays Gateways WC plugin for WordPress, specifically in versions through 1.3.7. The issue stems from a missing authorization check in a REST API endpoint, which allows unauthenticated users to access and modify plugin settings. This includes the ability to overwrite critical payment gateway information such as live API keys, secret keys, and payment tokens, all of which are stored in the 'woocommerce_ipospays_settings' option.
No patch is currently available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| May 18, 2026 | CVE Rejected | [email protected] |
| May 18, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |