CVE-2026-80342 Overview
CVE-2026-80342 affects the Payment Plugins for PayPal WooCommerce WordPress plugin in versions before 2.0.27. The plugin fails to verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid, unless that PayPal order has already been completed. Unauthenticated attackers can exploit this flaw to capture another buyer's approved but uncaptured PayPal payment against an order of their own. The vulnerability is classified as an Insecure Direct Object Reference [CWE-639]. It affects WooCommerce merchants who process payments through the vulnerable plugin.
Critical Impact
An unauthenticated attacker can hijack another buyer's approved PayPal payment and have it captured against their own WooCommerce order, causing financial loss to the original buyer and merchant.
Affected Products
- Payment Plugins for PayPal WooCommerce WordPress plugin versions prior to 2.0.27
- WooCommerce storefronts using the plugin for PayPal checkout
- WordPress sites with the plugin enabled and accepting PayPal payments
Discovery Timeline
- 2026-09-23 - CVE-2026-80342 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-80342
Vulnerability Analysis
The vulnerability resides in the payment capture flow of the Payment Plugins for PayPal WooCommerce plugin. When a customer submits a payment request, the plugin accepts a PayPal order identifier supplied in the request without validating that the identifier belongs to the WooCommerce order being paid. The plugin only enforces this binding when the PayPal order has already been completed, leaving approved-but-uncaptured orders unprotected. This gap enables an attacker to substitute another buyer's PayPal order identifier and have that payment captured against an order they control.
Root Cause
The root cause is a missing authorization check between two related object identifiers, matching the pattern described in [CWE-639: Authorization Bypass Through User-Controlled Key]. The plugin trusts client-supplied PayPal order identifiers instead of verifying ownership against the associated WooCommerce order and the requesting session. Because the check is conditionally applied only to completed PayPal orders, business logic bypass is possible during the approved state.
Attack Vector
Exploitation is network-based and requires no authentication or user interaction on the victim's account. An attacker places their own WooCommerce order on the vulnerable store, then supplies a PayPal order identifier corresponding to another buyer's approved-but-uncaptured payment. The plugin captures the mismatched PayPal payment and marks the attacker's WooCommerce order as paid. Obtaining a valid target PayPal order identifier is a prerequisite, contributing to the high attack complexity rating.
No verified public proof-of-concept code is available. Refer to the WPScan Vulnerability Report for additional technical context.
Detection Methods for CVE-2026-80342
Indicators of Compromise
- WooCommerce orders marked paid where the captured PayPal transaction identifier does not match the buyer or order metadata
- PayPal capture events referencing order identifiers created by different customer sessions or IP addresses
- Customer disputes or chargebacks reporting payments captured against unrelated merchant orders
- Repeated payment submissions from a single account referencing multiple unrelated PayPal order identifiers
Detection Strategies
- Reconcile WooCommerce order records against PayPal transaction reports to identify buyer-to-order identifier mismatches
- Review web server access logs for repeated POST requests to the plugin's payment capture endpoints from the same source
- Alert on WooCommerce orders where the paying PayPal account email differs from the WooCommerce customer email
- Correlate PayPal webhook events with WooCommerce order metadata to detect substitution of order identifiers
Monitoring Recommendations
- Enable verbose logging on the WooCommerce checkout and PayPal capture flows
- Monitor the plugin's REST and AJAX endpoints for anomalous request patterns and volume spikes
- Track PayPal capture-to-order binding metrics and flag deviations for manual review
- Configure alerts for chargeback and dispute rate increases that may indicate exploitation
How to Mitigate CVE-2026-80342
Immediate Actions Required
- Update the Payment Plugins for PayPal WooCommerce plugin to version 2.0.27 or later on all affected WordPress sites
- Audit recent WooCommerce orders and PayPal captures for evidence of mismatched buyer-to-order bindings
- Contact affected buyers and issue refunds where captured payments do not match the original WooCommerce order
- Rotate PayPal API credentials if compromise of order data is suspected
Patch Information
The vendor addressed the flaw in version 2.0.27 of the Payment Plugins for PayPal WooCommerce plugin. The fix enforces that a PayPal order supplied in a payment request must belong to the WooCommerce order being paid, regardless of the PayPal order's completion state. Administrators should apply the update through the WordPress plugin manager. See the WPScan Vulnerability Report for advisory details.
Workarounds
- Temporarily disable the Payment Plugins for PayPal WooCommerce plugin until the patched version can be deployed
- Restrict PayPal checkout to authenticated customers to increase auditability of payment requests
- Enable manual review for all PayPal capture events until the update is applied
- Deploy a web application firewall rule to inspect and rate-limit requests to the plugin's payment capture endpoints
# Update the plugin via WP-CLI
wp plugin update woo-paypal-gateway --version=2.0.27
# Verify the installed version
wp plugin get woo-paypal-gateway --field=version
# Temporarily deactivate if immediate patching is not possible
wp plugin deactivate woo-paypal-gateway
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
