{
 "id": "WPSEC-2026-0654",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0654/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0654/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0654/index.md",
 "title": "Stitch Express <= 1.9.1 - Unauthenticated Order Status Check Bypass via 'override' Parameter",
 "description": "The Stitch Express plugin for WordPress is vulnerable to an order status check bypass in versions 1.3.1 up to, and including, 1.9.1 via the 'override' parameter of the payment callback endpoint. This makes it possible for unauthenticated attackers who hold a paid Stitch Express payment for an order, such as that order's customer, to mark the order as paid while it is on hold.",
 "plugin": {
  "slug": "stitch-express",
  "name": "Stitch Express",
  "full_name": "Stitch Express",
  "wordpress_org": "https://wordpress.org/plugins/stitch-express/",
  "advisories_url": "https://wpsec.com/vuln/plugin/stitch-express/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/stitch-express"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-863"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.3.1",
    "from_inclusive": true,
    "to": "1.9.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.3.1 before 1.9.3"
  ]
 },
 "introduced_in": "1.3.1",
 "fixed_in": "1.9.3",
 "remediation": "Update to 1.9.3 or later.",
 "fix_released": "2026-10-07T13:05:43+00:00",
 "published": "2026-10-08T13:48:37+00:00",
 "updated": "2026-10-07T19:15:21.715878+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0654/",
  "https://plugins.svn.wordpress.org/stitch-express/tags/1.9.3/",
  "https://wordpress.org/plugins/stitch-express/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/stitch-express",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}