Skip to main content
Vulnerability Database/CVE-2026-80342

CVE-2026-80342: PayPal WooCommerce Auth Bypass Vulnerability

CVE-2026-80342 is an authentication bypass flaw in Payment Plugins for PayPal WooCommerce that lets attackers capture other buyers payments. This article covers technical details, affected versions, security impact, and mitigation.

Published:

CVE-2026-80342 Overview

CVE-2026-80342 affects the Payment Plugins for PayPal WooCommerce WordPress plugin in versions before 2.0.27. The plugin fails to verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid, unless that PayPal order has already been completed. Unauthenticated attackers can exploit this flaw to capture another buyer's approved but uncaptured PayPal payment against an order of their own. The vulnerability is classified as an Insecure Direct Object Reference [CWE-639]. It affects WooCommerce merchants who process payments through the vulnerable plugin.

Critical Impact

An unauthenticated attacker can hijack another buyer's approved PayPal payment and have it captured against their own WooCommerce order, causing financial loss to the original buyer and merchant.

Affected Products

  • Payment Plugins for PayPal WooCommerce WordPress plugin versions prior to 2.0.27
  • WooCommerce storefronts using the plugin for PayPal checkout
  • WordPress sites with the plugin enabled and accepting PayPal payments

Discovery Timeline

  • 2026-09-23 - CVE-2026-80342 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-80342

Vulnerability Analysis

The vulnerability resides in the payment capture flow of the Payment Plugins for PayPal WooCommerce plugin. When a customer submits a payment request, the plugin accepts a PayPal order identifier supplied in the request without validating that the identifier belongs to the WooCommerce order being paid. The plugin only enforces this binding when the PayPal order has already been completed, leaving approved-but-uncaptured orders unprotected. This gap enables an attacker to substitute another buyer's PayPal order identifier and have that payment captured against an order they control.

Root Cause

The root cause is a missing authorization check between two related object identifiers, matching the pattern described in [CWE-639: Authorization Bypass Through User-Controlled Key]. The plugin trusts client-supplied PayPal order identifiers instead of verifying ownership against the associated WooCommerce order and the requesting session. Because the check is conditionally applied only to completed PayPal orders, business logic bypass is possible during the approved state.

Attack Vector

Exploitation is network-based and requires no authentication or user interaction on the victim's account. An attacker places their own WooCommerce order on the vulnerable store, then supplies a PayPal order identifier corresponding to another buyer's approved-but-uncaptured payment. The plugin captures the mismatched PayPal payment and marks the attacker's WooCommerce order as paid. Obtaining a valid target PayPal order identifier is a prerequisite, contributing to the high attack complexity rating.

No verified public proof-of-concept code is available. Refer to the WPScan Vulnerability Report for additional technical context.

Detection Methods for CVE-2026-80342

Indicators of Compromise

  • WooCommerce orders marked paid where the captured PayPal transaction identifier does not match the buyer or order metadata
  • PayPal capture events referencing order identifiers created by different customer sessions or IP addresses
  • Customer disputes or chargebacks reporting payments captured against unrelated merchant orders
  • Repeated payment submissions from a single account referencing multiple unrelated PayPal order identifiers

Detection Strategies

  • Reconcile WooCommerce order records against PayPal transaction reports to identify buyer-to-order identifier mismatches
  • Review web server access logs for repeated POST requests to the plugin's payment capture endpoints from the same source
  • Alert on WooCommerce orders where the paying PayPal account email differs from the WooCommerce customer email
  • Correlate PayPal webhook events with WooCommerce order metadata to detect substitution of order identifiers

Monitoring Recommendations

  • Enable verbose logging on the WooCommerce checkout and PayPal capture flows
  • Monitor the plugin's REST and AJAX endpoints for anomalous request patterns and volume spikes
  • Track PayPal capture-to-order binding metrics and flag deviations for manual review
  • Configure alerts for chargeback and dispute rate increases that may indicate exploitation

How to Mitigate CVE-2026-80342

Immediate Actions Required

  • Update the Payment Plugins for PayPal WooCommerce plugin to version 2.0.27 or later on all affected WordPress sites
  • Audit recent WooCommerce orders and PayPal captures for evidence of mismatched buyer-to-order bindings
  • Contact affected buyers and issue refunds where captured payments do not match the original WooCommerce order
  • Rotate PayPal API credentials if compromise of order data is suspected

Patch Information

The vendor addressed the flaw in version 2.0.27 of the Payment Plugins for PayPal WooCommerce plugin. The fix enforces that a PayPal order supplied in a payment request must belong to the WooCommerce order being paid, regardless of the PayPal order's completion state. Administrators should apply the update through the WordPress plugin manager. See the WPScan Vulnerability Report for advisory details.

Workarounds

  • Temporarily disable the Payment Plugins for PayPal WooCommerce plugin until the patched version can be deployed
  • Restrict PayPal checkout to authenticated customers to increase auditability of payment requests
  • Enable manual review for all PayPal capture events until the update is applied
  • Deploy a web application firewall rule to inspect and rate-limit requests to the plugin's payment capture endpoints
bash
# Update the plugin via WP-CLI
wp plugin update woo-paypal-gateway --version=2.0.27

# Verify the installed version
wp plugin get woo-paypal-gateway --field=version

# Temporarily deactivate if immediate patching is not possible
wp plugin deactivate woo-paypal-gateway

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.