CVE-2026-83537 The WP Express Checkout WordPress plugin before 2.5.0… — CVE Notify — TG.ME

🚨 CVE-2026-83537
The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

🎖@cveNotify
WPScan
WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_payment
See details on WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_payment CVE 2026-83537. View the latest Plugin Vulnerabilities on WPScan.
September 9, 2026 67