Unrated severityNVD Advisory· Published Aug 10, 2026
CVE-2026-17016
CVE-2026-17016
Description
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=3.1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.