The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.
Title Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T11:00:05.130Z

Reserved: 2026-08-21T10:44:32.094Z

Link: CVE-2026-77765

cve-icon Vulnrichment

Updated: 2026-09-23T10:38:48.016Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:01.827

Modified: 2026-09-23T11:17:11.270

Link: CVE-2026-77765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses