rootpwn

medium · CVSS v3 5.3 · EPSS 0.00114

CVE-2026-92996

The Verge3D WordPress plugin (v4.1.0–4.13.0) allows unauthenticated users to mark any order as paid without verification. This flaw can lead

Overview

The Verge3D WordPress plugin (v4.1.0–4.13.0) allows unauthenticated users to mark any order as paid without verification. This flaw can lead to fraudulent orders and revenue loss. The issue is due to missing payment verification and order ownership checks.

Description

The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.

Impact

Confidentiality is minimally affected, but integrity is compromised as order status can be altered by attackers. Availability remains unaffected. Site owners, e-commerce managers, and payment processors are directly impacted by potential revenue loss and unauthorized content access.

Remediation

Upgrade to the latest Verge3D plugin version (≥4.14.0) where payment verification and order ownership checks are implemented. If an upgrade is not possible, disable the payment processing endpoint or restrict access to the order status endpoint to authenticated administrators only. Monitor order logs for suspicious status changes and audit payment workflows regularly.

Risk context

The vulnerability has a medium severity rating and a very low EPSS score (0.00114), indicating limited exploitation likelihood, but the potential impact on revenue warrants timely patching.

Affected products

  • Verge3D WordPress plugin

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
—
EPSS
0.00114

WordPress plugin payment order unauthenticated integrity verge3d

← All CVEs