CVE-2026-3461Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users in based solely on a user-supplied billing email address during guest checkout for subscription products, without verifying email ownership, requiring a password, or validating a one-time token. This makes it possible for unauthenticated attackers to log in as any existing user, including administrators, by providing the target user's email address in the billing_details parameter, resulting in complete account takeover and site compromise.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-15: 1Exploit Tool / Code · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 104-1504-1704-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-171
Disclosure1
2026-04-181
General1
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🌐 مدونة WordPress : 🪗 إضافة Accordion Slider (الأخطر): التقييم: 9.8 | (CVE-2026-6443) ⚠️عبارة عن Backdoor مزروع عمداً في الإصدار (1.4.6). 🧩 إضافات أخرى (بتقييم 9.8): ⚠️ تسمح برفع ملفات وتخطي المصادقة في الإضافات التالية: 📂 إضافة WebStack برقم (CVE-2026-1555) 💳 إضافة Visa Plugin برقم (CVE-2026-3461) 🔀 إضافة Barcode Scanner برقم (CVE-2026-4880)

    Post summary

    Four WordPress plugins (Accordion Slider, WebStack, Visa Plugin, Barcode Scanner) contain the newly disclosed CVEs CVE‑2026‑6443, CVE‑2026‑1555, CVE‑2026‑3461 and CVE‑2026‑4880, all rated 9.8 CVSS with a backdoor and authentication bypass that enable file upload and unauthorized access.

    110021.3K
    48.7K followersView on X
  • z3n@zench4n
    General

    Traditional vulnerability research focuses on memory corruption or auth bypass like CVE-2026-3461. In agentic systems, the threat shifts to indirect prompt injection. The vulnerability lies in the agent's inability to distinguish between developer instructions and data.

    Post summary

    The text discusses a shift toward prompt injection vulnerabilities in agentic systems, describing the issue but providing no PoC, exploit, active use, or patch information.

    100005
    1.4K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3461: Visa Acceptance Solutions <= 2.1.... One billing email parameter = instant admin takeover on any WordPress site running this payment plugin - authentication ... https://zerodaysignal.com/vulnerability/CVE-2026-3461 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE‑2026‑3461 in Visa Acceptance Solutions <= 2.1, noting that a single billing email parameter can cause instant admin takeover on WordPress sites, and links to a zero‑day signal page for further details.

    0000068
    218 followersView on X

Explore more