Tag
high
advisory
CVE-2026-15288: SureForms WordPress Plugin Payment Manipulation Vulnerability
1 rule 1 TTP 1 CVEThe SureForms - Drag and Drop Form Builder for WordPress plugin (versions up to and including 2.2.1) is vulnerable to improper input validation (CVE-2026-15288), allowing unauthenticated attackers to modify payment amounts in user-controlled POST data when submitting Stripe payment forms, enabling them to purchase products or services at arbitrarily reduced prices.
SureForms - Drag and Drop Form Builder for WordPress plugin <= 2.2.1
wordpress
plugin
vulnerability
web
payment-fraud
1r
1t
1c
critical
advisory
Systempay 1.0 Weak Crypto Allows Payment Signature Forging (CVE-2020-37168)
2 rules 1 TTP 1 CVESystempay 1.0 contains a weak cryptographic implementation vulnerability (CVE-2020-37168) allowing attackers to brute-force the production secret key, forge payment signatures, and manipulate transaction amounts.
Systempay 1.0
cve
credential-access
ecommerce
payment-fraud
2r
1t
1c
high
advisory
WeChat Pay Callback Signature Bypass via Host Header Manipulation
2 rules 1 TTPA vulnerability exists in yansongda/pay where signature verification is skipped when the Host header is `localhost`, allowing attackers to forge payment notifications.
yansongda/pay
wechatpay
signature-bypass
payment-fraud
webserver
2r
1t