Deema Payment Gateway WordPress 插件(版本 1.1.2 及更早版本)未对来自支付提供商的通知进行真实性校验,且默认情况下禁用该验证功能,导致未认证的攻击者可将未支付订单标记为已支付,或取消现有订单并执行退款。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Deema Payment Gateway | 0 ~ 1.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86786 | Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_ima | |
| CVE-2026-94299 | elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Cal | |
| CVE-2026-94278 | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat | |
| CVE-2026-94271 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverifi | |
| CVE-2026-89289 | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update R |
No comments yet