WordPress Plugin Vulnerabilities
Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
Description
The plugin does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
JunHee CHO
Submitter
JunHee CHO
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-28 (about 4 days ago)
Added
2026-09-28 (about 3 days ago)
Last Updated
2026-09-28 (about 3 days ago)