CVE-2026-92996
Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
| Vendor | unknown |
| Product | verge3d publishing and e-commerce |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown verge3d publishing and e-commerce
Be the first to know when new medium vulnerabilities affecting unknown verge3d publishing and e-commerce are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Verge3D Publishing and E-Commerce
4.1.0 ≤ 4.13.0
References
Credits
Pablo González Pérez Francisco José Ramírez Vicente Iñigo Sánchez Enciso WPScan