WordPress Plugin Vulnerabilities
WooCommerce PayPal Payments < 4.0.2 - Unauthenticated Order Manipulation and Sensitive Information Disclosure
Description
The plugin does not perform authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester's session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers' order payment flows and exfiltrate sensitive order details (payer information, shipping data).
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Dmitrii Ignatyev
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-05-22 (about 3 months ago)
Added
2026-05-26 (about 2 months ago)
Last Updated
2026-08-21 (about 2 days ago)