CVE-2026-77765
Received Received - Intake

Arbitrary Reduced Payment in Better Payment WordPress Plugin

Vulnerability report for CVE-2026-77765, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
better_payment better_payment to 2.3.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Better Payment WordPress plugin before version 2.3.4 has a flaw where it does not validate the payment amount on the server side against the merchant's fixed price. This allows unauthenticated users to submit a lower amount than intended and still complete the payment for fixed-price items.

Detection Guidance

To detect this vulnerability, check the installed version of the Better Payment WordPress plugin. If the version is below 2.3.4, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin files directly.

Impact Analysis

This vulnerability could allow attackers to pay less than the actual price for items, leading to financial losses for merchants. It may also undermine trust in the payment system and expose merchants to fraudulent transactions.

Compliance Impact

This vulnerability could lead to financial discrepancies in payment processing, potentially violating compliance requirements for accurate record-keeping and transaction integrity under standards like GDPR (data protection) and HIPAA (healthcare data). Unauthorized payment manipulation may result in improper financial reporting or audit failures.

Mitigation Strategies

Immediately update the Better Payment plugin to version 2.3.4 or later. Disable the plugin temporarily if an update is not immediately available. Monitor for unauthorized transactions and review payment logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77765. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart