Impact
The Accept PayPal & Stripe with Subscriptions for WooCommerce plugin allows a user to pay less than the order total and still have the order recorded as fully paid because the plugin does not compare the amount received in PayPal’s Data Transfer return against the expected amount. This logical flaw enables a payment bypass that can be abused to obtain goods or services without paying the correct amount, leading to financial loss and erosion of customer trust. The weakness reflects improper authorization (CWE‑284).
Affected Systems
WordPress sites that have installed the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin version 3.1.0 or earlier are the only systems impacted. No other plugins or WordPress components are currently known to be affected.
Risk and Exploitability
The CVSS score is 3.7, indicating moderate severity, and the EPSS estimate is below 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation can be carried out by any ordinary customer who initiates a purchase through PayPal, taking advantage of the Data Transfer feature. No special technical skills are required, but the attacker can extract a financial benefit by receiving goods or services for less than the expected payment. The impact is limited to monetary loss and reputational damage; the vulnerability does not grant code execution or privilege escalation.
OpenCVE Enrichment