Vulnerabilities / Stitch Express / WPSEC-2026-0654

Stitch Express <= 1.9.1 - Unauthenticated Order Status Check Bypass via 'override' Parameter

Low 3.7 CWE-863Fixed in 1.9.3
ID
WPSEC-2026-0654
Plugin
Stitch Express (stitch-express)
Affected
from 1.3.1 before 1.9.3
Remediation
Update to 1.9.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-863
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Stitch Express on WPSec AttackSurface
Fix released
Published

Description

The Stitch Express plugin for WordPress is vulnerable to an order status check bypass in versions 1.3.1 up to, and including, 1.9.1 via the 'override' parameter of the payment callback endpoint. This makes it possible for unauthenticated attackers who hold a paid Stitch Express payment for an order, such as that order's customer, to mark the order as paid while it is on hold.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0