CVE-2026-77765 PUBLISHED

Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation

Assigner: WPScan
Reserved: 21.08.2026 Published: 23.09.2026 Updated: 23.09.2026

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.

Product Status

Vendor Unknown
Product Better Payment
Versions Default: unaffected
  • affected from 0 to 2.3.4 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE