CVE-2026-17012

Summary

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.

Affected Software

VendorProductVersion RangeStatus
UnknownAccept PayPal & Stripe with Subscriptions for WooCommerce0 <= 3.1.0affected

Weaknesses

  • CWE-284 Improper Access Control

References