Description
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Order Manipulation via Unverified Webhook
Action: Immediate Patch
AI Analysis

Impact

The Deema Payment Gateway plugin for WordPress through version 1.1.2 does not verify the authenticity of payment provider notifications, and the plugin’s verification feature is disabled by default. This flaw allows an attacker who can send requests to the webhook endpoint to mark an unpaid order as paid, cancel an order, or trigger a refund, effectively manipulating transactional data without authentication. The vulnerability is a classic example of missing authentication for critical operations and improper access control, enabling attackers to alter financial records and potentially recover funds they are not entitled to.

Affected Systems

The only affected product is the Deema Payment Gateway WordPress plugin, with all versions up to and including 1.1.2 vulnerable. No specific operating system or platform constraints are mentioned beyond its use as a WordPress plugin.

Risk and Exploitability

This flaw exposes a high-impact exploitation path that an attacker can reach over the public internet by crafting a webhook payload. The lack of a public EPSS score means the exploitation probability is unknown, but the absence of any KEV listing does not diminish the seriousness for organizations using the plugin. Because an attacker can perform the attack without any prior authentication or privileged access, the risk is considered high.

Generated by OpenCVE AI on October 6, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Deema Payment Gateway to version 1.1.3 or later, where webhook verification is mandatory.
  • If an upgrade is not possible, enable the webhook verification setting in the plugin configuration and supply a shared secret or IP whitelist to restrict valid notification sources.
  • As a temporary workaround, temporarily disable the webhook integration or block all external POST requests to the plugin’s notification endpoint until a patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
CWE-639

Tue, 06 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.
Title Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via Webhook
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-06T06:00:20.623Z

Reserved: 2026-09-21T09:16:17.649Z

Link: CVE-2026-94270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T07:16:59.857

Modified: 2026-10-06T07:16:59.857

Link: CVE-2026-94270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:30:19Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-639

    Authorization Bypass Through User-Controlled Key