WordPress Plugin Vulnerabilities

Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done

Description

The plugin does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-25 (about 3 days ago)
Added
2026-09-18 (about 10 days ago)
Last Updated
2026-09-18 (about 10 days ago)

Other