CVE-2026-92996
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 28, 2026
Vendor
unknown
Description
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.