CVE-2026-89411: Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The affected range is Paymattic versions 4.6.20 through versions before 4.6.26. The provided information does not state whether any particular Paymattic payment configuration is required beyond use of Stripe payments and pending orders.
What does an attacker need to do to exploit this?
An attacker does not need authentication or user interaction. They must confirm a smaller Stripe payment of their own and use it to cause an arbitrary pending order to be marked as paid.
What is the practical impact?
An attacker may bypass the intended payment amount for a pending order by having it treated as paid after confirming a lower-value payment. The supplied severity vector indicates integrity impact, with no stated confidentiality or availability impact.