A vulnerability labeled as critical has been found in Xendit Payment Plugin up to 7.1.0 on WordPress. Affected is an unknown function. The manipulation results in improper access controls.

This vulnerability was named CVE-2026-66473. The attack may be performed from remote. There is no available exploit.