Impact
The vulnerability in Paymattic versions 4.6.20 through 4.6.25 allows unauthenticated users to confirm a Stripe PaymentIntent that marks an arbitrary pending order as paid, without verifying that the payment belongs to the order. This gives an attacker the ability to fraudulently acknowledge receipt of payment and potentially ignore the true payment amount. The result is a financial loss or fraudulent transaction that undermines the integrity of the e‑commerce process.
Affected Systems
WordPress installations running the Paymattic plugin before 4.6.26 are affected. The vulnerable code exists in the plugin’s order handling components that link Stripe payment confirmations to orders, but does not enforce a match between the order ID and the PaymentIntent. Only the plugin itself is impacted; the vulnerability is not tied to WordPress core.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. As the attack can be performed by unauthenticated users, an attacker only needs web access to the site and the ability to trigger a Stripe PaymentIntent, which is typically possible through the publicly exposed plugin endpoints. No additional credentials or privileges are required, making exploitation straightforward for anyone who can reach the site.
OpenCVE Enrichment