Executive brief
A security vulnerability exists in the Better Payment plugin for WordPress, which is used to process donations, subscriptions, and instant payments. The flaw allows unauthorized users to bypass certain access controls by providing manipulated quantity inputs. This could lead to unauthorized access to payment-related functions or disruptions in how donations and subscriptions are processed.
Technical details
The Better Payment plugin (versions <= 2.2.0) for WordPress suffers from an 'Improper Validation of Specified Quantity in Input' vulnerability (CWE-1284). This flaw allows an unauthenticated remote attacker to access functionality that is not properly constrained by Access Control Lists (ACLs) by manipulating input quantities. The vulnerability is rated with a CVSS 3.1 base score of 6.5, indicating a medium impact on integrity and availability. Users are advised to update to version 2.2.1 or later to remediate the issue.
Affected products
- WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More <= 2.2.0
Timeline
- 2026-05-23: disclosed: Reported by dodoh4t via Patchstack
- 2026-07-06: patched: Version 2.2.1 released
- 2026-07-13: advisory: NVD publication date