Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More <= 2.2.0 - Unauthenticated Business Logic Flaw
2026-07-07 00:00
dodoh4tStrategic Overview
StatusPatched in 2.2.1
Affected Version
<= 2.2.0CVSS5.3Medium
CVE
CVE-2026-57364Vulnerability Overview
The Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin for WordPress is vulnerable to a business logic flaw in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to alter input quantities.
Technical Analysis
REMEDIATION: Update to version 2.2.1, or a newer patched version --- IDENTIFIER: CWE-1284 (Improper Validation of Specified Quantity in Input) The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C