Deema Payment Gateway(WordPress插件)1.1.2及之前版本在处理托管式结账页面返回时,未向支付提供商验证支付信息,也未检查支付状态或金额,从而导致未授权用户可以将订单标记为“已支付”,而实际上并未进行任何真实支付。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Deema Payment Gateway | 0 ~ 1.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86786 | Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_ima | |
| CVE-2026-94299 | elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Cal | |
| CVE-2026-94270 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via | |
| CVE-2026-94278 | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat | |
| CVE-2026-89289 | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update R |
No comments yet