Sceawere

Vulnerability Detail

CVE-2026-89411UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Paymattic Payment Validation Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
Unknown
Product
Paymattic
Attack Type
CWE-345 Insufficient Verification of Data Authenticity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T07:17:21.387Z",
  "pubdate": "2026-09-28T07:17:21.387Z",
  "executiveSummary": "The Paymattic WordPress plugin, specifically versions 4.6.20 through 4.6.25, contains a critical input validation vulnerability affecting its Stripe payment integration mechanism.\nThis flaw is classified as a payment verification bypass, which allows unauthenticated remote attackers to manipulate the order fulfillment process.\nThe root cause lies in the application's failure to verify the cryptographic or logical association between a successful Stripe transaction event and the specific pending order record it is purportedly satisfying.\nBy submitting a separate, legitimate payment of a smaller value to Stripe, an attacker can leverage the resulting confirmation to trigger the plugin's backend logic to mark an arbitrary, higher-value pending order as 'paid'.\nThis vulnerability carries severe financial and operational risks, as it facilitates unauthorized access to digital goods or services without fulfilling the intended payment requirements.\nExploitation requires no authentication and can be performed over a network, making it a highly accessible vector for malicious actors seeking to circumvent e-commerce payment workflows.",
  "technicalDetails": "The vulnerability resides within the Paymattic Stripe payment processing module, specifically where the plugin handles incoming confirmations or webhooks related to transaction success.\nUnder normal operations, when a payment is processed via Stripe, the plugin receives a notification to update the order status. The flaw exists because the plugin fails to implement a strictly enforced server-side check that validates the 'Transaction ID' or 'PaymentIntent ID' against the specific 'Order ID' or 'Session ID' associated with the initial checkout request.\nAn attacker can exploit this lack of binding by initiating two concurrent processes. First, they identify an existing 'pending' order on the target site. Second, they initiate a new, separate payment transaction through the plugin's Stripe gateway for a nominal amount.\nOnce the attacker completes their own legitimate payment, they intercept the confirmation signal—typically sent as a callback or a redirect back to the site's processing endpoint—and modify the request parameters or sequence such that the system associates this successful payment confirmation with the target's pending order instead of their own session.\nBecause the server-side logic solely checks if 'a' payment was successful rather than 'the' specific payment requested for that order, the application updates the status of the victim's order to 'completed' or 'paid' in the database.\nThis behavior constitutes a classic Insecure Direct Object Reference (IDOR) or logic error in payment validation. The vulnerable component fails to perform an authorization check on the relationship between the PaymentIntent data retrieved from the Stripe API and the local WordPress post meta or custom tables governing the order fulfillment state.\nImpact analysis indicates that this vulnerability allows for the bypass of financial authorization protocols, leading to potential inventory exhaustion, unauthorized access to premium content, or illegitimate account credits. The attack is effective regardless of the user's authentication state, as the payment confirmation endpoint is often exposed to allow for third-party Stripe webhooks or client-side redirects.\nVersions 4.6.20 through 4.6.25 are confirmed to be vulnerable, as they lack the necessary integrity checks to prevent cross-referencing of transaction events."
}
CVE-2026-89411: Paymattic Payment Validation Bypass (MEDIUM Severity, CVSS: 5.3) | Sceawere