CVE-2026-77765
Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.
| Vendor | unknown |
| Product | better payment |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown better payment
Be the first to know when new unknown vulnerabilities affecting unknown better payment are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Better Payment
0 < 2.3.4
References
Credits
Muni Nitish Kumar Yaddala WPScan