CVE-2026-45209: WordPress MyCryptoCheckout plugin <= 2.161 - Broken Access Control vulnerability
Published May 25, 2026
·Updated
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.
Affected Software
1 affected component
edward_plainview MyCryptoCheckout<=2.161
Remediation
Information
Update the WordPress MyCryptoCheckout Plugin to the latest available version (at least 2.162).
Event History
May 25, 2026
CVE Published
via MITRE·10:31 PM
Data Sourced
via MITRE·10:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-45209?
The severity of CVE-2026-45209 is high with a score of 7.5.
2
How do I fix CVE-2026-45209?
To fix CVE-2026-45209, update the WordPress MyCryptoCheckout plugin to version 2.162 or later.
3
What type of vulnerability is CVE-2026-45209?
CVE-2026-45209 is categorized as a Broken Access Control vulnerability.
4
What versions of MyCryptoCheckout are affected by CVE-2026-45209?
CVE-2026-45209 affects MyCryptoCheckout versions from n/a through 2.161.
5
What can happen if CVE-2026-45209 is exploited?
If exploited, CVE-2026-45209 could allow attackers to improperly access restricted areas of the MyCryptoCheckout plugin.