๐Ÿ” CVE Alert

CVE-2026-16621

MEDIUM 5.3

Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying.

Vendor unknown
Product payment gateway for paypal on woocommerce
Published Aug 12, 2026
Last Updated Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown payment gateway for paypal on woocommerce

Be the first to know when new medium vulnerabilities affecting unknown payment gateway for paypal on woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Payment Gateway for PayPal on WooCommerce
0 < 9.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/76c4cff2-1166-45fe-9517-5eda2d24c35d/

Credits

Muni Nitish Kumar Yaddala WPScan