cleantalk
Vulnerabilities and Security Researches

Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP, CVE-2026-89411

CVE, Research URL

CVE-2026-89411

Published on
Sep 28, 2026
Research Description
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Affected versions
Min 4.6.20, max 4.6.26.
Status
vulnerable