Medium severity5.3NVD Advisory· Published Aug 12, 2026· Updated Aug 12, 2026
CVE-2026-16990
CVE-2026-16990
Description
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.2.3.44
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.