CVE-2026-92996
MEDIUMCVSS 5.3/10
Last modified
CVE-2026-92996 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid..
Description
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Verge3D Publishing and E-Commerce | >= 4.1.0, <= 4.13.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-92996?
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
How severe is CVE-2026-92996?
CVE-2026-92996 has a CVSS score of 5.3/10 (MEDIUM severity).
How do I fix CVE-2026-92996?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92987roxmltree through 0.21.1 performs quadratic-time attribute a…7.5
- CVE-2026-9299A flaw has been found in omec-project amf up to 2.1.1. Affec…6.3
- CVE-2026-92991The Biggop Library is vulnerable to Cross-Site Scripting via…5.4
- CVE-2026-92992A security vulnerability has been detected in Dromara mayfly…6.3
- CVE-2026-92993A vulnerability was detected in Dromara mayfly-go up to 1.11…6.3
- CVE-2026-92995The Verge3D Publishing and E-Commerce WordPress plugin throu…5.3
- CVE-2026-9300A vulnerability has been found in omec-project amf up to 2.1…6.3
- CVE-2026-93000The SPS-Suite WordPress plugin through 1.4.0 does not saniti…6.8
- CVE-2026-9301A vulnerability was found in omec-project amf up to 2.1.1. T…6.3
- CVE-2026-93012Email::Sender::Transport::Sendmail versions before 2.602 for…9.8
- CVE-2026-93013RAGFlow through 0.27.2 contains a path traversal vulnerabili…4.3
- CVE-2026-93014RosarioSIS versions before 12.9 fail to validate the filenam…7.1
Are you affected by CVE-2026-92996?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
