MEDIUM
Paymattic
CVE published 2026-09-28
CVE-2026-89411
The Paymattic WordPress plugin, versions 4.6.20 through 4.6.26, contains a vulnerability that allows unauthenticated users to mark arbitrary pending orders as paid. This is possible because the plugin does not verify that a confirmed Stripe payment belongs to the order it is applied to. The vulnerability could lead to financial discrepancies if exploited. Defenders responsible for WordPress installations [truncated]