← Zurück zur CVE-Suche

CVE-2026-9284

WooCommerce PayPal Payments

Beschreibung

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester-s session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers- order payment flows and exfiltrate sensitive order details (payer information, shipping data) by creating a PayPal order for a victim-s WC order and then retrieving the PayPal order data.

CVSS 8.2EPSS 0.40099999999999997%Risiko 0.85
Quelle öffnen
Veröffentlicht
2026-05-23 05:16:34
Betroffene Versionen
<=4.0.1
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N