cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-payment-form wp-payment-form

Direction: descending
Sep 30, 2026

Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # CVE-2026-89411

CVE, Research URL

CVE-2026-89411

Date
Sep 28, 2026
Research Description
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Affected versions
Min 4.6.20, max 4.6.26.
Status
vulnerable
Jun 16, 2026

Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # 9ff8a652-2340-476d-8430-70b203c023e1

Date
-
Research Description
Paymattic &#8211; Secure, Simple Payment &amp; Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 Best Payments Plugin for WP &lt; 4.2.1 - Reflected Cross-Site Scripting The plugin does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Affected versions
max 4.2.1.
Status
vulnerable

Simple Payment Donations &amp; Subscriptions Plugin by Paymattic &#8211; Best Payments Plugin for WP # b6106dd9bc47fc566edd8b2a51e8e46221dd1b18

Date
Aug 10, 2022
Research Description
Paymattic &#8211; Secure, Simple Payment &amp; Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 Simple Payment Donations <= 4.2.0 - Reflected Cross-Site Scripting The Simple Payment Donations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 4.2.1.
Status
vulnerable
May 06, 2026
Jun 06, 2024

Simple Payment Donations &amp; Subscriptions Plugin by Paymattic &#8211; Best Payments Plugin for WP # eb8c3b246ed634de3b474b2fd400a792d258a3ea

Date
Aug 10, 2022
Research Description
Paymattic &#8211; Secure, Simple Payment &amp; Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 WordPress Best Payments Plugin for WP plugin <= 4.2.0 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Best Payments Plugin for WP plugin (versions <= 4.2.0). Update the WordPress Best Payments Plugin for WP plugin to the latest available version (at least 4.2.1).
Affected versions
max 4.2.1.
Status
vulnerable

Simple Payment Donations &amp; Subscriptions Plugin by Paymattic &#8211; Best Payments Plugin for WP # CVE-2022-2565

CVE, Research URL

CVE-2022-2565

Date
Sep 05, 2022
Research Description
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins
Affected versions
max 4.2.1.
Status
vulnerable