WhisperX tag archive

#payment-bypass

This page collects WhisperX intelligence signals tagged #payment-bypass. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Vault · 2026-05-11 12:10:36 · GitHub Issues

1. WBcom Credits SDK Checkout Bypass Allows Arbitrary Credit Purchases at Manipulated Prices

A critical pricing-manipulation vulnerability has been identified in the WBcom Credits SDK, exposing any consuming application to direct financial loss. The checkout endpoint at `POST /wp-json/wbcom-credits/v1/{slug}/checkout/{gateway}` accepts both `credits` and `price_cents` parameters directly from the client withou...