Description
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Payment Bypass
Action: Apply Patch
AI Analysis

Impact

The Verge3D WordPress plugin, between versions 4.1.0 and 4.13.0, omits a crucial verification step with its payment gateway and does not confirm that an order belongs to the user initiating the request, allowing an unauthenticated request to the v3d_payment_done endpoint to mark any order as paid. This flaw is a form of authorization bypass, enabling attackers to receive paid content or services without completing the legitimate payment process. The lack of proper validation permits compromise of the monetary integrity of the site, potential loss of revenue, and breach of trust with customers.

Affected Systems

The affected system is the Verge3D WordPress plugin, used by Verge3D Publishing and E-Commerce. All installations of the plugin from release 4.1.0 through 4.13.0 are vulnerable, regardless of host WordPress configuration. No specific CPE string is provided, but the scope includes all sites running these plugin versions.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there may be limited public exploitation data. However, the public nature of the plugin and the fact that the payment confirmation endpoint can be reached without authentication indicate a likely web‑based attack vector. An attacker with shallow technical skills could craft a request to the vulnerable endpoint, bypass payment verification, and gain access to paid content or services.

Generated by OpenCVE AI on September 28, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Verge3D plugin to a version where payment verification and order ownership checks are enforced, ensuring that all orders are validated against the payment provider before marking them as complete.
  • Until a patched version is available, disable or restrict access to the v3d_payment_done endpoint so that only authenticated administrative users can trigger it.
  • Add an additional server‑side verification step that confirms the payment status returned by the payment gateway before updating any order records, thereby mitigating the flaw even if the plugin update is delayed.

Generated by OpenCVE AI on September 28, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
Title Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-28T06:19:22.475Z

Reserved: 2026-09-17T14:09:49.913Z

Link: CVE-2026-92996

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:21.500

Modified: 2026-09-28T07:17:21.500

Link: CVE-2026-92996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key