WordPress Plugin Vulnerabilities

Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order

Description

The plugin does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-07-06 (about 2 months ago)
Added
2026-07-06 (about 2 months ago)
Last Updated
2026-09-15 (about 2 days ago)

Other