CVE-2026-57364
Deferred Deferred - Pending Action

Improper Input Validation in Better Payment Plugin

Vulnerability report for CVE-2026-57364, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More: from n/a through <= 2.2.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpdeveloper better_payment to 2.2.0 (inc)
wpdeveloper better_payment to 2.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Validation of Specified Quantity in Input issue found in the WPDeveloper Better Payment plugin, which handles instant payments, donations, fundraising with subscriptions, and more. It allows accessing functionality that is not properly constrained by Access Control Lists (ACLs), meaning unauthorized users might be able to perform actions or access features they should not have permission to.

Detection Guidance

To detect this vulnerability on your system, you can check the installed version of the Better Payment WordPress plugin. The vulnerability affects versions 2.2.0 or below.

  • Log in to your WordPress admin dashboard.
  • Navigate to 'Plugins' and locate 'Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More'.
  • Check the version number displayed next to the plugin name. If it is 2.2.0 or below, your system is vulnerable.

Alternatively, you can check the plugin version via the command line if you have access to the WordPress installation directory.

  • Run the following command to list the installed plugins and their versions: wp plugin list --path=/path/to/wordpress
  • Look for 'better-payment' in the output and verify its version.
Impact Analysis

The vulnerability can lead to unauthorized access to certain functionalities within the Better Payment plugin. This could result in improper manipulation of payment or subscription processes, potentially causing integrity and availability issues such as unauthorized changes or disruptions in payment handling.

Compliance Impact

The vulnerability in the Better Payment plugin involves improper validation of input and improper access control, which could allow unauthorized access to functionality. This may have implications for compliance with standards and regulations depending on the context in which the plugin is used.

  • GDPR: If the plugin processes personal data of EU citizens, the vulnerability could lead to unauthorized access or manipulation of payment or donation data, potentially violating GDPR's requirements for data protection and access control (Articles 5, 25, and 32).
  • HIPAA: If the plugin is used in a healthcare setting to process payments or donations involving protected health information (PHI), the vulnerability could result in unauthorized access to PHI, violating HIPAA's Security Rule (45 CFR Part 164, Subpart C).

However, the CVSS score of 6.5 and the classification as low risk suggest that the immediate impact may be limited. The vulnerability does not directly indicate exposure of sensitive data but could enable unauthorized actions that might indirectly lead to compliance violations if not mitigated.

Mitigation Strategies

The immediate step to mitigate this vulnerability is to update the Better Payment plugin to the latest patched version.

  • Log in to your WordPress admin dashboard.
  • Navigate to 'Plugins' and find 'Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More'.
  • If an update is available, click 'Update Now' to upgrade to version 2.2.1 or later.

If you are using Patchstack, you can enable auto-updates for vulnerable plugins to ensure timely patching.

  • Go to your Patchstack dashboard and enable auto-updates for the Better Payment plugin.

If you cannot update immediately, consider disabling the plugin temporarily until the update is applied to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57364. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart