---
id: CVE-2026-94270
title: >-
  The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the
  authenticity of incoming payment provider notifications, and ships with that
  verification disabled by default, allowing unauthenticated attackers to mark
  an unp…
summary: >-
  The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the
  authenticity of incoming payment provider notifications, and ships with that
  verification disabled by default, allowing unauthenticated attackers to mark
  an unp…
severity: none
cwe:
  - CWE-287
product: Deema Payment Gateway
affected:
  - deema_payment_gateway <= 1.1.2
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:59.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94270'
references:
  - url: 'https://wpscan.com/vulnerability/9db2eff1-d605-44c3-aa3e-f65410f8e87b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T06:48:36.105Z'
---

## Overview

The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
