WordPress · Wp Express Checkout · CVE-2026-83533
**Name of the Vulnerable Software and Affected Versions**
WP Express Checkout versions prior to 2.4.9
**Description**
Unauthenticated users can forge a completed order without making a payment because the software fails to verify server-side that a payment was actually completed before marking an order as paid. This issue occurs within the `wpec process payment()` function.
**Recommendations**
Update WP Express Checkout to version 2.4.9 or later.