Sceawere
Vulnerability Detail
CVE-2026-90987UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insecure Payment Amount Validation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- Easy PayPal & Stripe Buy Now Button
- Attack Type
- CWE-472 External Control of Assumed-Immutable Web Parameter
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T07:16:38.370Z",
"pubdate": "2026-10-02T07:16:38.370Z",
"executiveSummary": "The Easy PayPal & Stripe Buy Now Button WordPress plugin, in versions prior to 2.0.6, contains a critical vulnerability related to improper input validation during the transaction process.\nThe vulnerability allows an unauthenticated attacker to manipulate the final payment amount transmitted to the payment gateway.\nThis flaw exists because the plugin fails to perform server-side verification of the transaction price, instead relying on parameters provided by the client-side request.\nBy intercepting and modifying the price parameter during the checkout process, an attacker can complete a purchase for an arbitrary, significantly lower price than intended.\nThis represents a direct financial risk to the site owner, as it enables unauthorized economic gain and potential loss of goods or services.\nThe vulnerability is accessible remotely via the internet and does not require the attacker to possess any form of authentication or high-level privileges on the target WordPress installation.",
"technicalDetails": "The vulnerability is categorized as an insecure input validation issue, where the plugin fails to maintain a secure server-side source of truth for financial transactions.\nThe root cause of this flaw is the reliance on client-supplied data for critical business logic. When a user initiates a purchase, the plugin constructs a payment request—intended for PayPal or Stripe—using pricing data sourced directly from the browser's request payload.\nBecause the server does not perform an integrity check or compare the submitted price against the actual product price stored in the database, the transaction amount is inherently untrusted.\nThe attack flow proceeds as follows: 1. An attacker initiates a purchase process on a page utilizing the Easy PayPal & Stripe Buy Now Button plugin. 2. Before the request reaches the payment provider's API, the attacker uses an intercepting proxy (such as Burp Suite) to intercept the HTTP request containing the transaction parameters. 3. The attacker locates the specific parameter responsible for the transaction amount and modifies its value to an arbitrarily low price (e.g., changing $100.00 to $0.01). 4. The proxy forwards the modified request to the third-party payment gateway.\nBecause the gateway receives a valid-looking request with the manipulated amount, it processes the payment based on the attacker's input. The server-side code of the plugin fails to reconcile the completed payment notification (IPN or Webhook) against the original intended price, effectively confirming an order that was paid for at an unauthorized rate.\nThis vulnerability affects all versions of the Easy PayPal & Stripe Buy Now Button plugin prior to 2.0.6. There are no authentication requirements for an attacker to exploit this, as the checkout process is typically publicly accessible. The network exposure is absolute, as any internet-connected user can interact with the plugin's frontend components. The post-exploitation impact includes financial loss to the merchant and the ability to obtain goods or services for fractions of their intended cost, potentially bypassing inventory management and revenue tracking systems."
}