Junglewise Threat Intelligence

CVE-2026-39643: Payment Plugins PayPal WooCommerce missing authorization

CVE-2026-39643 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: Payment Plugins for PayPal WooCommerce. Vendors: Payment Plugins.

Executive brief

A security vulnerability exists in the Payment Plugins for PayPal WooCommerce plugin, which is used by WordPress sites to process PayPal transactions. The flaw allows unauthorized individuals to bypass certain access controls due to incorrectly configured security levels. While the impact is considered limited, it could allow unauthenticated users to perform actions that should be restricted to administrators or the system itself.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Payment Plugins for PayPal WooCommerce plugin (pymntpl-paypal-woocommerce) for WordPress. The issue stems from incorrectly configured access control security levels within the plugin's functional logic. An unauthenticated remote attacker can exploit this flaw to execute restricted actions without proper permission. The vulnerability is rated with a CVSS 3.1 base score of 5.3, primarily impacting integrity. Users are advised to upgrade to version 2.0.14 or later to remediate the issue.

Affected products

  • Payment Plugins Payment Plugins for PayPal WooCommerce <= 2.0.13

Timeline

  • 2026-01-15: other: Vulnerability reported by researcher Nguyen Ba Khanh
  • 2026-02-14: patched: Version 2.0.14 released to address the vulnerability
  • 2026-04-08: disclosed: CVE published to NVD

References

Related threats