Junglewise Threat Intelligence

CVE-2026-80340: Payment Plugins for PayPal WooCommerce information disclosure

CVE-2026-80340 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Payment Plugins for PayPal WooCommerce.

Executive brief

The Payment Plugins for PayPal WooCommerce plugin displays sensitive order data (customer names, billing and shipping addresses, order totals) in unauthenticated HTML pages without proper access controls. An attacker can enumerate sequential order IDs and extract the order encryption key from page source, then use it to view any customer's complete order details and personal information.

Technical details

The plugin fails to validate the WooCommerce order key before embedding order objects into JavaScript configuration on the checkout order-pay page. This allows unauthenticated users to enumerate sequential order IDs (e.g., /checkout/order-pay/1/, /checkout/order-pay/2/, etc.) and extract the order_key secret from the page HTML source, despite WooCommerce displaying an "invalid order" error to the user interface. Armed with the disclosed order_key, an attacker can access the order-received endpoint with any order ID and receive the full customer-facing order view, exposing PII including customer name, email, billing address, shipping address, and order line items. No authentication, session cookies, or non-default configuration is required. The vulnerability is fixed in version 2.0.26.

Affected products

  • Payment Plugins for PayPal Payment Plugins for PayPal WooCommerce before 2.0.26

Timeline

  • 2026-09-07: disclosed
  • 2026-09-09: advisory
  • 2026-09-09: patched: Fixed in version 2.0.26

References