Impact
The plugin‑ecommerce service in Payload CMS uses the Stripe payment adapter, and before version 3.90.0 the adapter can process an order confirmation more than once under certain conditions, allowing a duplicate order to be created. This flaw is a constraint violation identified as CWE‑837, resulting in inadvertent double processing of a single payment request. The duplicate processing can cause financial loss, inventory mis‑recording, and customer disputes, compromising the integrity of transaction data.
Affected Systems
The vulnerability affects Payload CMS plugin‑ecommerce and the core Payload CMS product. Versions prior to 3.90.0 of the plugin and prior to 4.0.0‑canary.34 of the core are impacted; these are all releases that have been in use before the patch.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is assessed as high severity. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog, indicating no publicly confirmed exploitation at the time of this analysis. The likely attack vector is a remote attacker sending or replaying a Stripe webhook event that confirms an order; the attacker requires access to the webhook endpoint or a forged Stripe signature, which can be mitigated by validating Stripe signatures and ensuring idempotent order handling.
OpenCVE Enrichment
Github GHSA