rootpwn

medium · CVSS v3 5.3 · EPSS 0.00186

CVE-2026-77765

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the …

Description

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS
0.00186

← All CVEs