CVE-2026-16621

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 12:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-16621

Mitre link : CVE-2026-16621

CVE.ORG link : CVE-2026-16621


JSON object : View

Products Affected

No product.

CWE

No CWE.