Executive brief
A security vulnerability exists in the Payment Gateway for PayPal on WooCommerce plugin, which is used by WordPress sites to process PayPal transactions. An unauthorized attacker could exploit this flaw to perform actions that should be restricted to administrators, potentially interfering with payment processing or order management. This could lead to unauthorized changes in transaction data or operational disruptions for online stores.
Technical details
The Payment Gateway for PayPal on WooCommerce plugin (versions <= 9.1.4) contains a broken access control vulnerability due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this flaw by sending crafted requests to the affected site, allowing them to execute functions that should be restricted to privileged users. The vulnerability has a CVSS score of 7.5, primarily impacting data integrity. The issue is resolved in version 9.1.5.
Affected products
- Easy Payment Payment Gateway for PayPal on WooCommerce <= 9.1.4
Timeline
- 2026-07-09: other: Reported by researcher Ananda Dhakal
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD dataset
- 2026-07-23: patched: Fix available in version 9.1.5