CVE-2026-90987: Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price
The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using Easy PayPal & Stripe Buy Now Button versions before 2.0.6 are affected if they use the plugin to process purchases with a client-provided payment amount.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They can manipulate the client-supplied price field to attempt a purchase at an arbitrarily lower amount.
What should be done if patching cannot happen immediately?
The provided information does not describe a workaround. Until the plugin is updated to 2.0.6 or later, review purchases processed through the affected plugin for unexpectedly low payment amounts.