<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:payload_cms:payloadcms_plugin_ecommerce:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apayload_cmspayloadcms_plugin_ecommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:47:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apayload_cmspayloadcms_plugin_ecommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Duplicate Order Processing in Payload Ecommerce Stripe Adapter</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-ecommerce-race/</link><pubDate>Tue, 06 Oct 2026 18:47:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-ecommerce-race/</guid><description>A logic flaw in the @payloadcms/plugin-ecommerce Stripe payment adapter allows order confirmations to be processed multiple times, posing a risk of duplicate fulfillment.</description><content:encoded><![CDATA[<p>Payload CMS has disclosed a vulnerability in the @payloadcms/plugin-ecommerce package that impacts the handling of Stripe payment adapter events. Under specific conditions, an order confirmation can be processed more than once, potentially leading to duplicate transaction processing or redundant order fulfillment. This issue affects versions prior to 3.90.0 and certain 4.0.0-canary releases. This flaw is identified as CVE-2026-105850 and relates to the atomicity or idempotency of the confirmation processing logic within the plugin.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this logic flaw can result in financial discrepancies, unauthorized duplicate orders, and inventory or fulfillment errors for affected e-commerce deployments. The scope is limited to systems utilizing the @payloadcms/plugin-ecommerce with Stripe integration.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of the @payloadcms/plugin-ecommerce package to version 3.90.0 or higher, or 4.0.0-canary.34 or higher, to resolve CVE-2026-105850. In environments where immediate patching is not feasible, implement idempotency checks at the application or database layer to ensure Stripe webhooks related to order confirmation are only processed once per unique transaction identifier.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>