CVE-2026-16621
Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying.
| Vendor | unknown |
| Product | payment gateway for paypal on woocommerce |
| Published | Aug 12, 2026 |
| Last Updated | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown payment gateway for paypal on woocommerce
Be the first to know when new medium vulnerabilities affecting unknown payment gateway for paypal on woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Payment Gateway for PayPal on WooCommerce
0 < 9.2.1
References
Credits
Muni Nitish Kumar Yaddala WPScan