Executive brief
The WP Express Checkout WordPress plugin allows unauthenticated visitors to forge completed payment orders without actually paying. By manipulating a publicly accessible checkout form, attackers can generate valid order confirmations and access digital products meant to be purchased. This bypasses the plugin's payment gateway entirely, enabling free access to paid content.
Technical details
The plugin fails to verify server-side that a payment was actually completed before marking an order as paid. The vulnerability exists in the wpec_process_empty_payment AJAX action, which processes free/empty payments. An unauthenticated attacker can extract the nonce and product ID from the public checkout page, then submit a forged payment request via AJAX that hardcodes the transaction status to COMPLETED without contacting any payment gateway. The plugin then generates a valid order with wpec_order_state=paid, allowing download of the product. No authentication or privilege escalation is required—the attack works entirely through public endpoints.
Affected products
- WP Express Checkout WP Express Checkout before 2.5.0
Timeline
- 2026-09-07: disclosed
- 2026-09-09: patched: Fixed in version 2.5.0