CVE-2026-32587

WordPress WP EasyPay plugin <= 4.2.11 - Broken Access Control vulnerability

Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.


We have discovered 332 live websites that are affected by CVE-2026-32587.

Run a Free Instant Scan




Affected Software

Product  Wp Easy Pay
Category Wordpress Plugins
Vulnerable Domains332 live websites (95% of Wp Easy Pay install base)
Vulnerable Versions
  • from 0 through 4.2.11
Vulnerable Versions Count2 versions ( 67% of all versions)



Details

  • Published - Mar 16, 2026
  • Updated - Apr 1, 2026

Credits

  • Nabil Irawan | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32587
United States286 websites



Canada17 websites
Australia10 websites
GB4 websites
Singapore3 websites
Cyprus2 websites
France2 websites
Bulgaria1 websites
Ireland1 websites

Website Distribution by TLD

Number of websites using CVE-2026-32587
.com190 websites
.org101 websites
.ca9 websites
.net8 websites
.com.au7 websites
.co.uk4 websites
.info2 websites
.it1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32587

Top websites that are affected by CVE-2026-32587. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States***,***
******************.org United States***,***
********.org United States***,***
***************.info United States*,***,***
************.org United States*,***,***
************.org Bulgaria*,***,***
**********.org United States*,***,***
********.school United States*,***,***
*******************.com United States*,***,***
************.com Japan*,***,***
See full domain list

FAQ

A total of 332 websites have been identified as vulnerable to CVE-2026-32587, based on global website indexing conducted by WebTechSurvey.
The Wp Easy Pay is affected by the CVE-2026-32587 vulnerability.
Wp Easy Pay versions up to and including 4.2.11 are vulnerable to CVE-2026-32587.