Impact
The Accept PayPal & Stripe with Subscriptions for WooCommerce plugin releases through version 3.1.0 fail to verify that the PayPal account that receives the payment matches the merchant’s configured account before marking an order as paid. This omission allows unauthenticated buyers to complete a WooCommerce order by directing the full payment to their own PayPal account; the plugin then records the order as paid, creating the appearance of a legitimate transaction while the merchant never receives the funds.
Affected Systems
Any WordPress site that installs the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin at a version of 3.1.0 or earlier is vulnerable. The issue is independent of other WooCommerce components and does not require additional plugins or configurations to manifest.
Risk and Exploitability
The vulnerability is a payment bypass that gives an attacker the ability to defraud the merchant by changing the receiver_email field. While no publicly disclosed exploits are listed and EPSS is unavailable, the attack vector is inferred to involve a front‑end transaction where the buyer can supply an arbitrary PayPal email. The risk is high because any user can trigger the bypass, the attacker does not need privileged access, and the outcome is a loss of revenue for the merchant. The CVSS score is not explicitly provided, but the potential for financial loss and relatively low effort exploitation place this vulnerability in a high‑severity category. It is not listed in CISA’s KEV catalog, but the lack of KEV status does not reduce the urgency of remediation.
OpenCVE Enrichment