---
id: CVE-2026-94271
title: >-
  The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the
  payment with the payment provider when handling the return from the hosted
  checkout, and does not check the payment status or amount, allowing
  unauthenticated u…
summary: >-
  The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the
  payment with the payment provider when handling the return from the hosted
  checkout, and does not check the payment status or amount, allowing
  unauthenticated u…
severity: none
cwe:
  - CWE-287
product: Deema Payment Gateway
affected:
  - deema_payment_gateway <= 1.1.2
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:59.973'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94271'
references:
  - url: 'https://wpscan.com/vulnerability/9455978a-b406-4456-9054-a516c117bdbf/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T06:48:36.104Z'
---

## Overview

The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
