SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-57364

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Better Payment plugin for WordPress is vulnerable due to improper validation of input quantities, which allows unauthorized access to functionality not properly constrained by Access Control Lists (ACLs). This could lead to potential exploitation, enabling attackers to manipulate payment processes or access sensitive features. Organizations using versions up to 2.2.0 of this plugin should prioritize patching to mitigate the risk of unauthorized access and financial fraud.

CVE
CVE-2026-57364
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More: from n/a through <= 2.2.0.