WordPress Plugin Vulnerabilities

WooCommerce PayPal Payments < 4.0.2 - Unauthenticated Order Manipulation and Sensitive Information Disclosure

Description

The plugin does not perform authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester's session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers' order payment flows and exfiltrate sensitive order details (payer information, shipping data).

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Verified
No

Timeline

Publicly Published
2026-05-22 (about 3 months ago)
Added
2026-05-26 (about 2 months ago)
Last Updated
2026-08-21 (about 2 days ago)

Other