Executive brief
WC PayPay Gateway is a WordPress plugin that processes payments for WooCommerce stores through the PayPay payment provider. The plugin fails to verify that payment notifications come from PayPay, allowing attackers with only knowledge of a store's merchant ID to forge fake payment confirmations, mark arbitrary orders as paid, and prevent legitimate customer orders from being processed. This can result in fraudulent transactions, order fulfillment disputes, and revenue loss.
Technical details
The plugin implements a webhook handler for payment notifications from PayPay but fails to cryptographically verify the authenticity of incoming requests before processing them. An unauthenticated attacker who knows the target store's PayPay merchant ID can send a forged JSON payload to the webhook endpoint (/?wc-api=wc_paypay) with arbitrary order state changes (COMPLETED, AUTHORIZED, CANCELED, FAILED, EXPIRED). The plugin accepts these requests without verifying a signature or other authentication token, immediately updating the corresponding WooCommerce order status, reducing inventory, and sending customer notifications. The merchant ID is typically public or easily discoverable (e.g., by placing a test order). No patch has been released as of the advisory date.
Affected products
- WC PayPay Gateway WC PayPay Gateway 0.5 to 0.9.3
Timeline
- 2026-09-09: disclosed
- 2026-09-11: advisory