CVE-2026-83537 - WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_payment
CVE ID :CVE-2026-83537
Published : Sept. 9, 2026, 6:25 a.m. | 40 minutes ago
Description :The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 9, 2026, 6:25 a.m. | 40 minutes ago
Description :The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...