WordPress Plugin Vulnerabilities

SKT PayPal for WooCommerce < 1.5 - Unauthenticated Payment Bypass

Description

The plugin is vulnerable to Payment Bypass due to the plugin only enforcing client side controls instead of server-side controls when processing payments. This makes it possible for unauthenticated attackers to make confirmed purchases without actually paying for them.

Affects Plugins

References

Miscellaneous

Original Researcher
ch4r0n
Verified
No

Timeline

Publicly Published
2025-11-26 (about 4 months ago)
Added
2025-11-27 (about 4 months ago)
Last Updated
2025-11-27 (about 4 months ago)

Other