CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-94271: Deema Payment Gateway 0 through 1.1.2

CVE-2026-94271. CVSS 3.1 base score 5.3 (MEDIUM, Source advisory).

Affected technology

Deema Payment Gateway · 0 through 1.1.2
Vendor not specified by the source

Description’s affected range: through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says the Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken. Source advisory’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low.

Published

CWE
CWE-287
CCR priority
21.2 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94271.html