PatchSiren

Paymattic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Paymattic CVE published 2026-09-28

CVE-2026-89411

The Paymattic WordPress plugin, versions 4.6.20 through 4.6.26, contains a vulnerability that allows unauthenticated users to mark arbitrary pending orders as paid. This is possible because the plugin does not verify that a confirmed Stripe payment belongs to the order it is applied to. The vulnerability could lead to financial discrepancies if exploited. Defenders responsible for WordPress installations [truncated]