CVE-2026-17012 PUBLISHED

Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email

Assigner: WPScan
Reserved: 24.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.

Product Status

Vendor Unknown
Product Accept PayPal & Stripe with Subscriptions for WooCommerce
Versions Default: unknown
  • affected from 0 to 3.1.0 (incl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE