VYPR

Payment Plugins For Paypal Woocommerce

by WordPress

CVEs (4)

  • CVE-2026-13399HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

  • CVE-2026-80341MedSep 9, 2026
    risk 0.38cvss 5.9epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then…

  • CVE-2026-80340MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and,…

  • CVE-2026-39643MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13.