CVE-2026-89411 - Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent
CVE ID :CVE-2026-89411
Published : Sept. 28, 2026, 6:19 a.m. | 53 minutes ago
Description :The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 28, 2026, 6:19 a.m. | 53 minutes ago
Description :The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...