Impact
The Easy PayPal & Stripe Buy Now Button plugin calculates the payment amount on the server only in versions 2.0.6 and newer. Earlier releases (1.8 through 2.0.5) rely on a value supplied by the client, which an attacker can modify to lower the price of any transaction. This flaw allows an unauthenticated user to submit a forged payment request that records the merchant as receiving a reduced amount, causing direct financial loss for the site operator and potentially eroding revenue streams.
Affected Systems
WordPress sites that have the Easy PayPal & Stripe Buy Now Button plugin installed in versions 1.8 through 2.0.5 are affected. The vendor is listed as Unknown:Easy PayPal & Stripe Buy Now Button, and the vulnerability impacts all sites that use the plugin to process PayPal or Stripe payments.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is < 1%, and the vulnerability is not catalogued in the CISA KEV list. Based on the description, it is inferred that the attacker can manipulate the displayed and submitted price by altering the amount field on the client side and submitting a purchase request. Because the flaw is unprotected by authentication, exploitation is possible from any user that can reach the payment form, making the risk moderate upon presence of the vulnerable plugin.
OpenCVE Enrichment