PT-2026-84751 · WordPress · Wp Express Checkout
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Express Checkout versions prior to 2.4.9
Description
Unauthenticated users can forge a completed order without making a payment because the software fails to verify server-side that a payment was actually completed before marking an order as paid. This issue occurs within the
wpec process payment() function.Recommendations
Update WP Express Checkout to version 2.4.9 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Express Checkout