CVE-2026-12966 | Direct Payments Plugin up to 2.5.2 on WordPress AJAX access control
A vulnerability was found in Direct Payments Plugin up to 2.5.2 on WordPress and classified as problematic. The impacted element is an unknown function of the component AJAX Handler. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-12966. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More