Junglewise Threat Intelligence

CVE-2026-42655: Best Payments Plugin for WP payment bypass

CVE-2026-42655 · Severity: medium · CVSS 5.9 · Published 2026-06-15

Executive brief

The Best Payments Plugin for WordPress, which facilitates online transactions, contains a security flaw that allows unauthorized users to bypass payment processes. An attacker could potentially complete a checkout or access restricted content without making a valid payment. This could lead to financial loss and unauthorized access to paid services or digital goods.

Technical details

The Best Payments Plugin for WP (versions 4.6.19 and below) is vulnerable to a payment bypass classified as CWE-472 (External Control of Assumed-Immutable Web Parameter). The vulnerability allows an unauthenticated remote attacker to manipulate web parameters that the application assumes are immutable, effectively bypassing the payment verification logic. While the attack complexity is rated as high (AC:H), a successful exploit enables the attacker to achieve unauthorized integrity changes, such as marking a transaction as paid without a successful gateway response. The issue is resolved in version 4.6.20.

Affected products

  • Best Payments Plugin for WP Best Payments Plugin for WP <= 4.6.19

Timeline

  • 2026-03-19: other: Vulnerability reported by researcher
  • 2026-04-29: advisory: Patchstack advisory published
  • 2026-04-29: patched: Version 4.6.20 released
  • 2026-06-15: disclosed: CVE published to NVD

References