CVE-2026-16990
Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
| Vendor | unknown |
| Product | payment button for paypal |
| Published | Aug 12, 2026 |
| Last Updated | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown payment button for paypal
Be the first to know when new medium vulnerabilities affecting unknown payment button for paypal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Payment Button for PayPal
0 โค 1.2.3.44
References
Credits
Muni Nitish Kumar Yaddala WPScan