Popis
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester-s session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers- order payment flows and exfiltrate sensitive order details (payer information, shipping data) by creating a PayPal order for a victim-s WC order and then retrieving the PayPal order data.
- Zverejnené
- 2026-05-23 05:16:34
- Dotknuté verzie
- <=4.0.1
- Typ
- Webová aplikácia
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N