Description
The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Payment amount manipulation
Action: Update Plugin
AI Analysis

Impact

The Easy PayPal & Stripe Buy Now Button plugin calculates the payment amount on the server only in versions 2.0.6 and newer. Earlier releases (1.8 through 2.0.5) rely on a value supplied by the client, which an attacker can modify to lower the price of any transaction. This flaw allows an unauthenticated user to submit a forged payment request that records the merchant as receiving a reduced amount, causing direct financial loss for the site operator and potentially eroding revenue streams.

Affected Systems

WordPress sites that have the Easy PayPal & Stripe Buy Now Button plugin installed in versions 1.8 through 2.0.5 are affected. The vendor is listed as Unknown:Easy PayPal & Stripe Buy Now Button, and the vulnerability impacts all sites that use the plugin to process PayPal or Stripe payments.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is < 1%, and the vulnerability is not catalogued in the CISA KEV list. Based on the description, it is inferred that the attacker can manipulate the displayed and submitted price by altering the amount field on the client side and submitting a purchase request. Because the flaw is unprotected by authentication, exploitation is possible from any user that can reach the payment form, making the risk moderate upon presence of the vulnerable plugin.

Generated by OpenCVE AI on October 2, 2026 at 15:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Easy PayPal & Stripe Buy Now Button to version 2.0.6 or later, which enforces server‑side calculation of the payment amount.
  • Disable the plugin until the update is applied to prevent any further price manipulation attacks.
  • If the plugin cannot be updated, replace it with a trusted alternative, or implement server‑side validation of the transaction amount in your custom payment code to ensure no client‑supplied values are used.

Generated by OpenCVE AI on October 2, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-472
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
Title Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:10.258Z

Reserved: 2026-09-14T13:55:59.930Z

Link: CVE-2026-90987

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:35.705Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T07:16:38.370

Modified: 2026-10-02T18:00:34.733

Link: CVE-2026-90987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:00:13Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter