CVE-2026-92996: Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done
Published Sep 28, 2026
·Updated
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
Affected Software
1 affected component
Soft8Soft Verge3D WordPress plugin>=4.1.0<=4.13.0
Event History
Sep 28, 2026
CVE Published
via MITRE·06:19 AM
Data Sourced
via MITRE·06:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote user can exploit it. No account, user interaction, or payment-provider verification is required.
2
What must an attacker know to affect an order?
The attacker needs to target an order, because the vulnerable payment-completion functionality allows any order to be marked as paid without checking ownership. The provided data does not specify how order identifiers are obtained.
3
Which plugin versions are affected?
Soft8Soft Verge3D WordPress plugin versions 4.1.0 through 4.13.0 are affected.