CVE-2026-94271
Received Received - Intake

Unauthenticated Payment Bypass in Deema Payment Gateway WordPress Plugin

Vulnerability report for CVE-2026-94271, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: WPScan

Description

The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Deema Payment Gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Deema Payment Gateway WordPress plugin through version 1.1.2 has a flaw where it does not verify payments with the payment provider when returning from a hosted checkout. This allows unauthenticated users to trick the system into marking orders as paid without any actual payment being made.

Detection Guidance

Check if the Deema Payment Gateway WordPress plugin version 1.1.2 or below is installed. Review server logs for unauthorized order status changes marked as paid without payment processing.

Impact Analysis

This vulnerability could lead to financial losses as orders may be marked as paid without receiving actual payment. It also undermines trust in the payment system and could result in unauthorized transactions being processed.

Mitigation Strategies

Update the Deema Payment Gateway plugin to the latest version. Verify payment processing logic to ensure proper validation with the payment provider before marking orders as paid.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94271. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart