CVE-2026-90987

Summary

The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.

Affected Software

VendorProductVersion RangeStatus
UnknownEasy PayPal & Stripe Buy Now Button1.8 < 2.0.6affected

Weaknesses

  • CWE-472 External Control of Assumed-Immutable Web Parameter

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References