PT-2026-99778 · WordPress · Paymattic
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Paymattic WordPress plugin versions 4.6.20 through 4.6.25
Description
The plugin fails to verify if a confirmed Stripe payment is associated with the specific order it is being applied to. This allows unauthenticated users to mark any pending order as paid by confirming a smaller payment of their own against that order.
Recommendations
Update Paymattic WordPress plugin to version 4.6.26.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paymattic