PT-2026-57682 · Wpdeveloper+1 · Better Payment – Instant Payments+1

CVE-2026-57364

·

Published

2026-07-07

·

Updated

2026-07-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More versions prior to 2.2.1
Description A business logic flaw exists due to improper validation of specified quantities in input. This allows unauthenticated attackers to access functionality not properly constrained by Access Control Lists (ACLs), which are security mechanisms that define which users or systems are granted access to specific objects. Consequently, attackers can alter input quantities.
Recommendations Update to a version newer than 2.2.0.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57364

Affected Products

Better Payment – Instant Payments
Better-Payment