Payment Gateway Plugin Vulnerability in Deema by WordPress
CVE-2026-94270

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 October 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-94270?

The Deema Payment Gateway plugin for WordPress, up to version 1.1.2, has a significant security issue due to its failure to verify the authenticity of incoming payment provider notifications. This vulnerability occurs because the verification feature is disabled by default, enabling unauthorized attackers to falsely mark unpaid orders as paid, or to manipulate existing orders by canceling or refunding them without proper authorization. This flaw poses a serious risk for e-commerce operations relying on this plugin for transaction security.

Affected Version(s)

Deema Payment Gateway 0 <= 1.1.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo González Pérez
Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
WPScan
.