CVE-2026-77765: Unknown Better Payment

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.

Affected products

  • Unknown Better Payment: before 2.3.4 (fixed in 2.3.4)

Published 2026-09-23. Last modified 2026-09-23.