WordPress Plugin Vulnerabilities

Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation

Description

The plugin does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.

Proof of Concept

Affects Plugins

No known fix

References

Miscellaneous

Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-08-05 (about 28 days ago)
Added
2026-07-29 (about 1 month ago)
Last Updated
2026-08-25 (about 8 days ago)

Other