Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP, CVE-2026-89411
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Published on
- Sep 28, 2026
- Research Description
- The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
- Affected versions
-
Min 4.6.20, max 4.6.26.
- Status
-
vulnerable