CVE WATCH / VULNERABILITY DETAIL
CVE-2026-94271
MEDIUMCVSS 5.3NVD feed
Published 6 October 2026 · tracked since 7 October 2026
Description
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being ta
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-4889
- CVE-2026-41559 HIGH 7.5
- CVE-2026-39797 CRITICAL 9.8
- CVE-2026-39775 HIGH 8.8
- CVE-2026-39752 HIGH 7.7
- CVE-2026-39728 HIGH 7.2
- CVE-2026-32579 CRITICAL 10
- CVE-2026-105808 LOW 3.5
- CVE-2026-105809 MEDIUM 4.3
- CVE-2026-105059 MEDIUM 6.5