Executive brief
The Payment Gateway for PayPal plugin for WooCommerce fails to verify that incoming payment notifications come from PayPal's production environment and are intended for the store's own merchant account. An attacker can forge payment notifications using their own PayPal sandbox account to trick the store into marking orders as paid without genuine payment, leading to loss of revenue and inventory.
Technical details
The plugin does not validate the payment environment source or merchant account ID when processing IPN (Instant Payment Notification) callbacks from PayPal, allowing unauthenticated attackers to submit crafted notifications that mark orders complete. An attacker with a personal PayPal sandbox account can generate legitimate sandbox transactions and replay them to the vulnerable store. The vulnerability was fixed in version 9.2.1.
Affected products
- WooCommerce Payment Gateway for PayPal before 9.2.1
Timeline
- 2026-09-17: disclosed
- 2026-09-21: patched: Version 9.2.1 released