Medium severity5.3NVD Advisory· Published Sep 9, 2026
CVE-2026-83537
CVE-2026-83537
Description
The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
Affected products
2<2.5.0+ 1 more
- (no CPE)range: <2.5.0
- (no CPE)range: <2.5.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.