{"id":"CVE-2026-77765","title":"The Better Payment  WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbit…","summary":"The Better Payment  WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbit…","severity":"none","cwe":["CWE-284"],"product":"Better Payment","affected":["better_payment < 2.3.4"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T06:17:01.827","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77765","references":[{"url":"https://wpscan.com/vulnerability/932f8c74-1ded-40ee-b1fd-a328f3626f21/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T06:17:57.884Z","slug":"CVE-2026-77765","body":"## Overview\n\nThe Better Payment  WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}