Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More <= 2.2.0 - Unauthenticated Business Logic Flaw

2026-07-07 00:00
dodoh4t

Vulnerability Overview

The Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin for WordPress is vulnerable to a business logic flaw in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to alter input quantities.

Technical Analysis

REMEDIATION: Update to version 2.2.1, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C