{"id":"CVE-2026-87841","title":"The UnitechPay  WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as we…","summary":"The UnitechPay  WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as we…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:18.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87841","references":[{"url":"https://wpscan.com/vulnerability/f04babb4-2dee-4c41-8b4c-0c2428009180/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00136,"epssPercentile":0.02647,"ingestedAt":"2026-10-09T07:28:22.266Z","slug":"CVE-2026-87841","body":"## Overview\n\nThe UnitechPay  WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218540,"id":"CVE-2026-87841","ts":1791561812329,"field":"cvss","old":null,"new":"5.3"},{"seq":218539,"id":"CVE-2026-87841","ts":1791561812329,"field":"severity","old":"none","new":"medium"}]}