Junglewise Threat Intelligence

CVE-2026-92400: Payment Gateway for PayPal on WooCommerce payment verification bypass

CVE-2026-92400 · Severity: medium · CVSS 5.3 · Published 2026-09-21

Vendors: WooCommerce.

Executive brief

The Payment Gateway for PayPal plugin for WooCommerce fails to verify that incoming payment notifications come from PayPal's production environment and are intended for the store's own merchant account. An attacker can forge payment notifications using their own PayPal sandbox account to trick the store into marking orders as paid without genuine payment, leading to loss of revenue and inventory.

Technical details

The plugin does not validate the payment environment source or merchant account ID when processing IPN (Instant Payment Notification) callbacks from PayPal, allowing unauthenticated attackers to submit crafted notifications that mark orders complete. An attacker with a personal PayPal sandbox account can generate legitimate sandbox transactions and replay them to the vulnerable store. The vulnerability was fixed in version 9.2.1.

Affected products

  • WooCommerce Payment Gateway for PayPal before 9.2.1

Timeline

  • 2026-09-17: disclosed
  • 2026-09-21: patched: Version 9.2.1 released

References