CVE-2026-90987
Received Received - Intake

Arbitrary Price Manipulation in Easy PayPal & Stripe Buy Now Button WordPress Plugin

Vulnerability report for CVE-2026-90987, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easy_paypal_and_stripe_buy_now_button plugin From 1.8 (inc) to 2.0.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Easy PayPal & Stripe Buy Now Button WordPress plugin. It allows unauthenticated attackers to set an arbitrary lower price for a purchase by manipulating a client-supplied field that determines the payment amount. The plugin fails to validate or derive the price on the server side, enabling price manipulation.

Detection Guidance

Check the installed version of the Easy PayPal & Stripe Buy Now Button plugin in your WordPress admin panel. If the version is between 1.8 and 2.0.5, the system is vulnerable. Compare the version against the latest release 2.0.6 or higher.

Impact Analysis

If you use the affected plugin versions (1.8 to 2.0.5), an attacker could purchase items at a lower price than intended, leading to financial losses. Since no authentication is required, anyone can exploit this vulnerability remotely.

Compliance Impact

This vulnerability could lead to unauthorized price manipulation during transactions, potentially violating financial transaction integrity requirements under GDPR and HIPAA. It may also undermine data protection measures if payment data is improperly handled due to incorrect pricing logic.

Mitigation Strategies

Update the plugin to version 2.0.6 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Monitor network traffic for unusual payment requests with manipulated amounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90987. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart