๐Ÿ” CVE Alert

CVE-2026-92400

MEDIUM 5.3

Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.

Vendor unknown
Product payment gateway for paypal on woocommerce
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for unknown payment gateway for paypal on woocommerce

Be the first to know when new medium vulnerabilities affecting unknown payment gateway for paypal on woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Payment Gateway for PayPal on WooCommerce
0 < 9.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3dcee743-a95d-4233-b78e-8449a6cc8aea/

Credits

Charles Vosburgh WPScan