216.73.216.10

CVE-2026-2892

· Published 30/04/2026 14:16 · Modified 30/04/2026 14:52

Labels: CVE-2026-2892 2026-04-30CVE-2026-2892CWE-285[email protected]

Essential information

Published
30/04/2026 14:16
Modified
30/04/2026 14:52
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated users. The 'check_purchase' method trusts this cookie data without performing server-side verification against the Stripe API for one-time 'payment' mode purchases. This makes it possible for unauthenticated attackers to bypass Stripe purchase-gated content visibility conditions by forging the 'o_stripe_data' cookie with a target product ID, which is publicly exposed in the checkout block's HTML source.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / otter blocks cpe:2.3:a:wordpress:otter_blocks:3.1.4:*:*:*:*:wordpress:*:*
wordpress / otter blocks cpe:2.3:a:wordpress:otter_blocks:*:*:*:*:*:wordpress:*:*

References