WordPress Plugin Vulnerabilities

Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price

Description

The plugin does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.

Proof of Concept

Affects Plugins

Fixed in 2.0.6

References

Miscellaneous

Original Researcher
JunHee CHO
Submitter
JunHee CHO
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-28 (about 4 days ago)
Added
2026-09-28 (about 3 days ago)
Last Updated
2026-09-28 (about 3 days ago)

Other