Security Advisory
CVE-2026-83533
5.3
MEDIUM
Vulnerability Description
The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
Published Date
September 2, 2026
Official Source
NIST NVD Advisory