← Back to CVE search

CVE-2026-9284

WooCommerce PayPal Payments

Description

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester-s session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers- order payment flows and exfiltrate sensitive order details (payer information, shipping data) by creating a PayPal order for a victim-s WC order and then retrieving the PayPal order data.

CVSS 8.2EPSS 0.40099999999999997%Risk 0.85
View source
Published
2026-05-23 05:16:34
Affected versions
<=4.0.1
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N