CVE-2026-83533 The WP Express Checkout WordPress plugin before 2.4.9… — CVE Notify — TG.ME

🚨 CVE-2026-83533
The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

🎖@cveNotify
WPScan
WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment
See details on WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment CVE 2026-83533. View the latest Plugin Vulnerabilities on WPScan.
September 2, 2026 25