---
id: CVE-2026-87841
title: >-
  The UnitechPay  WordPress plugin through 1.0.6.3 does not verify the
  authenticity of the payment notifications it receives, allowing
  unauthenticated attackers to mark orders placed through it as paid without any
  payment being made, as we…
summary: >-
  The UnitechPay  WordPress plugin through 1.0.6.3 does not verify the
  authenticity of the payment notifications it receives, allowing
  unauthenticated attackers to mark orders placed through it as paid without any
  payment being made, as we…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T15:17:18.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87841'
references:
  - url: 'https://wpscan.com/vulnerability/f04babb4-2dee-4c41-8b4c-0c2428009180/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00136
epssPercentile: 0.02647
ingestedAt: '2026-10-09T07:28:22.266Z'
---

## Overview

The UnitechPay  WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
