{"id":"CVE-2026-90987","title":"The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.","summary":"The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-472"],"product":"Easy PayPal & Stripe Buy Now Button","affected":["easy_paypal_stripe_buy_now_button >= 1.8 < 2.0.6"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T11:17:36.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90987","references":[{"url":"https://wpscan.com/vulnerability/7c1faee8-628a-41dc-a5f0-afbc56480a18/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-02T10:48:18.811017Z"},"ingestedAt":"2026-10-02T07:13:06.669Z","slug":"CVE-2026-90987","body":"## Overview\n\nThe Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}