WordPress Plugin Vulnerabilities

Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverified Success Return

Description

The plugin does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Enrico Marcolini - Claudio Marchesini - Dottor Marc
Submitter
Enrico Marcolini - Claudio Marchesini - Dottor Marc
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-03 (about 2 days ago)
Added
2026-09-26 (about 9 days ago)
Last Updated
2026-09-26 (about 9 days ago)

Other