CVE-2026-94270
Received Received - Intake

Deema Payment Gateway WordPress Plugin Authentication Bypass

Vulnerability report for CVE-2026-94270, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: WPScan

Description

The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Deema Payment Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Deema Payment Gateway WordPress plugin up to version 1.1.2. It allows unauthenticated attackers to manipulate order statuses by exploiting improper authentication in payment provider notifications. The plugin does not verify these notifications by default, enabling attackers to mark unpaid orders as paid or cancel/refund existing orders without authorization.

Detection Guidance

Check if the Deema Payment Gateway WordPress plugin version 1.1.2 or earlier is installed. Look for unauthorized order modifications, such as unpaid orders marked as paid or refunds without transactions.

Impact Analysis

If you use this plugin, attackers could exploit it to alter order statuses, leading to financial losses from unpaid orders marked as paid or unauthorized refunds. It could also disrupt business operations by canceling valid orders or cause reputational damage due to incorrect transaction handling.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to financial or personal data during order manipulation. GDPR requires secure processing of personal data, while HIPAA mandates protection of health-related payment information. Exploitation may violate these regulations.

Mitigation Strategies

Disable the Deema Payment Gateway plugin immediately if installed. Monitor order statuses for unauthorized changes. Wait for an official patch or update from the plugin developers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94270. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart