medium · CVSS v3 5.3 · EPSS 0.00114
CVE-2026-92996
The Verge3D WordPress plugin (v4.1.0–4.13.0) allows unauthenticated users to mark any order as paid without verification. This flaw can lead
Overview
The Verge3D WordPress plugin (v4.1.0–4.13.0) allows unauthenticated users to mark any order as paid without verification. This flaw can lead to fraudulent orders and revenue loss. The issue is due to missing payment verification and order ownership checks.
Description
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
Impact
Confidentiality is minimally affected, but integrity is compromised as order status can be altered by attackers. Availability remains unaffected. Site owners, e-commerce managers, and payment processors are directly impacted by potential revenue loss and unauthorized content access.
Remediation
Upgrade to the latest Verge3D plugin version (≥4.14.0) where payment verification and order ownership checks are implemented. If an upgrade is not possible, disable the payment processing endpoint or restrict access to the order status endpoint to authenticated administrators only. Monitor order logs for suspicious status changes and audit payment workflows regularly.
Risk context
The vulnerability has a medium severity rating and a very low EPSS score (0.00114), indicating limited exploitation likelihood, but the potential impact on revenue warrants timely patching.
Affected products
- Verge3D WordPress plugin
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00114