CVE-2026-94270: Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via Webhook
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable verification of the authenticity of incoming payment provider notifications; it is disabled by default.
Deema Payment Gateway WordPress plugin Incoming payment notification authenticity verification = enabled
Event History
Frequently Asked Questions
Which sites are exposed by default?
WordPress sites using Deema Payment Gateway through version 1.1.2 are exposed because payment-notification authenticity verification is disabled by default.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They need to be able to send payment provider notification requests to the affected plugin.
What could an attacker do to affected orders?
An attacker can mark an unpaid order as paid, or cancel or refund an existing order.