Description
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Payment Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Paymattic versions 4.6.20 through 4.6.25 allows unauthenticated users to confirm a Stripe PaymentIntent that marks an arbitrary pending order as paid, without verifying that the payment belongs to the order. This gives an attacker the ability to fraudulently acknowledge receipt of payment and potentially ignore the true payment amount. The result is a financial loss or fraudulent transaction that undermines the integrity of the e‑commerce process.

Affected Systems

WordPress installations running the Paymattic plugin before 4.6.26 are affected. The vulnerable code exists in the plugin’s order handling components that link Stripe payment confirmations to orders, but does not enforce a match between the order ID and the PaymentIntent. Only the plugin itself is impacted; the vulnerability is not tied to WordPress core.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. As the attack can be performed by unauthenticated users, an attacker only needs web access to the site and the ability to trigger a Stripe PaymentIntent, which is typically possible through the publicly exposed plugin endpoints. No additional credentials or privileges are required, making exploitation straightforward for anyone who can reach the site.

Generated by OpenCVE AI on September 28, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Paymattic plugin to version 4.6.26 or later, which adds verification that the Stripe PaymentIntent belongs to the specific order before marking it as paid.
  • If an upgrade cannot be performed immediately, restrict access to the Paymattic order management interface so that only authenticated administrators can initiate payment confirmations.
  • Review the order placement flow to ensure that any Stripe PaymentIntent is matched against the corresponding order ID; add server‑side validation to detect mismatches and reject them.

Generated by OpenCVE AI on September 28, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-640

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Title Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-28T06:19:21.817Z

Reserved: 2026-09-11T16:27:21.951Z

Link: CVE-2026-89411

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:21.387

Modified: 2026-09-28T07:17:21.387

Link: CVE-2026-89411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password