Payment Gateway Plugin Vulnerability in Deema by WordPress
CVE-2026-94270
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 October 2026
Badges
What is CVE-2026-94270?
The Deema Payment Gateway plugin for WordPress, up to version 1.1.2, has a significant security issue due to its failure to verify the authenticity of incoming payment provider notifications. This vulnerability occurs because the verification feature is disabled by default, enabling unauthorized attackers to falsely mark unpaid orders as paid, or to manipulate existing orders by canceling or refunding them without proper authorization. This flaw poses a serious risk for e-commerce operations relying on this plugin for transaction security.
Affected Version(s)
Deema Payment Gateway 0 <= 1.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.