WordPress Plugin Vulnerabilities
SKT PayPal for WooCommerce < 1.5 - Unauthenticated Payment Bypass
Description
The plugin is vulnerable to Payment Bypass due to the plugin only enforcing client side controls instead of server-side controls when processing payments. This makes it possible for unauthenticated attackers to make confirmed purchases without actually paying for them.
Affects Plugins
References
Miscellaneous
Original Researcher
ch4r0n
Verified
No
WPVDB ID
Timeline
Publicly Published
2025-11-26 (about 4 months ago)
Added
2025-11-27 (about 4 months ago)
Last Updated
2025-11-27 (about 4 months ago)