Junglewise Threat Intelligence

CVE-2026-59547: Easy Payment PayPal for WooCommerce broken access control

CVE-2026-59547 · Severity: high · CVSS 7.5 · Published 2026-07-23

Executive brief

A security vulnerability exists in the Payment Gateway for PayPal on WooCommerce plugin, which is used by WordPress sites to process PayPal transactions. An unauthorized attacker could exploit this flaw to perform actions that should be restricted to administrators, potentially interfering with payment processing or order management. This could lead to unauthorized changes in transaction data or operational disruptions for online stores.

Technical details

The Payment Gateway for PayPal on WooCommerce plugin (versions <= 9.1.4) contains a broken access control vulnerability due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this flaw by sending crafted requests to the affected site, allowing them to execute functions that should be restricted to privileged users. The vulnerability has a CVSS score of 7.5, primarily impacting data integrity. The issue is resolved in version 9.1.5.

Affected products

  • Easy Payment Payment Gateway for PayPal on WooCommerce <= 9.1.4

Timeline

  • 2026-07-09: other: Reported by researcher Ananda Dhakal
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset
  • 2026-07-23: patched: Fix available in version 9.1.5

References