Impact
The Subscriptions for WooCommerce WordPress plugin prior to version 2.0.1 fails to validate a client‑supplied PayPal capture token and does not compare the captured amount to the WooCommerce order total. When a capture status of COMPLETED is received, the plugin marks the order as paid regardless of whether the token belongs to that order or whether the amount matches. This flaw permits an attacker to supply a legitimate, uncaptured PayPal order token from another transaction and have an expensive order marked paid without any payment actually occurring, resulting in fraudulent revenue for the store owner.
Affected Systems
The vulnerability affects all releases of the Subscriptions for WooCommerce WordPress plugin older than 2.0.1. No other vendors or products are reported as impacted.
Risk and Exploitability
The CVSS score is 5.9, indicating moderate severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated attacker submitting a crafted PayPal capture token during the WooCommerce order‑received flow when guest checkout is enabled. The requirement for a valid PayPal token from a prior approved order limits the attack, but does not eliminate the risk; an attacker could acquire such a token through phishing or account compromise. Once the token is supplied, the plugin blindly marks the order paid, leading to fraudulent revenue or unrecouped losses for the merchant.
OpenCVE Enrichment