WordPress Plugin Vulnerabilities
WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment
Description
The plugin does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Amity Gilmour
Submitter
Amity Gilmour
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-01 (about 1 day ago)
Added
2026-09-01 (about 1 day ago)
Last Updated
2026-09-01 (about 1 day ago)