Impact
The Better Payment WordPress plugin before version 2.3.4 fails to validate the amount submitted by a user against the merchant’s fixed price on the server side. This flaw allows an unauthenticated user to submit an arbitrary, lower charge for a fixed‑price item. The consequence is that customers can pay less than the intended amount, causing revenue loss and damaging trust. The weakness is an access control failure (CWE-284).
Affected Systems
WordPress sites that have the Better Payment plugin installed with a version earlier than 2.3.4 are affected. Any installation presenting the fixed‑price payment interface without upgrading the plugin is vulnerable.
Risk and Exploitability
The vulnerability’s CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the flaw is not in the CISA KEV catalog. Likely attack vector is a simple web request to the payment form, requiring no credentials. Exploitation is straightforward for anyone who can reach the plugin’s payment endpoint, potentially impacting the merchant’s revenue stream.
OpenCVE Enrichment