The Paymattic WordPress plugin from 4.6.20 before 4.6.26...
Moderate severity
Unreviewed
Published
Sep 28, 2026
to the GitHub Advisory Database
•
Updated Sep 28, 2026
Description
Published by the National Vulnerability Database
Sep 28, 2026
Published to the GitHub Advisory Database
Sep 28, 2026
Last updated
Sep 28, 2026
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
References