Impact
The Payment Button for PayPal plugin allows a client to specify a payment amount that is not checked against the merchant's configured price on the server. An unauthenticated attacker can therefore send a request that creates a real PayPal order for an arbitrary lower amount, resulting in revenue loss for the merchant. This flaw represents an improper input validation weakness that can be exploited without logging in or possessing administrative privileges.
Affected Systems
All WordPress sites running the Payment Button for PayPal plugin version 1.2.3.44 or earlier are affected. The vendor for the plugin is not disclosed, but it is listed as "Unknown:Payment Button for PayPal."
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact and medium exploitability. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Likely deployment involves a remote attacker sending a specially crafted payment request to the public endpoint; no authentication is required, so the vulnerability can be leveraged by anyone with network access to the target site. Although the flaw does not give direct code execution or privilege escalation, the financial loss and fraud potential elevate the business risk.
OpenCVE Enrichment