{
  "id": "CVE-2026-94271",
  "url": "https://spydr.io/cve/CVE-2026-94271",
  "published": "2026-10-06T07:16:59.973Z",
  "modified": "2026-10-06T11:17:30.737Z",
  "score": 5.3,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "score_source": "CISA ADP",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [],
  "products": [
    "Deema Payment Gateway"
  ],
  "cwes": [
    "CWE-287"
  ],
  "description": "The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken.",
  "status": "Received",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.3,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/9455978a-b406-4456-9054-a516c117bdbf/",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94271",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
