{"id":"CVE-2026-89411","published":"2026-09-28T07:17:21.387","lastModified":"2026-09-28T16:38:58.950","description":"The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-345"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/240a0440-7892-4c03-b282-2fdb6f086bb6/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}