Impact
The Accept PayPal & Stripe with Subscriptions for WooCommerce plugin up to version 3.1.0 fails to compare the amount received in PayPal’s Data Transfer return against the order total. This omission allows a user to pay less than the requested amount and still have the order recorded as completed, creating a clear payment bypass that can be abused for financial gain. The weakness is an example of missing input validation (CWE‑640).
Affected Systems
WordPress sites that have installed the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin, version 3.1.0 or earlier, are the only systems affected. No other plugins or WordPress components are known to be impacted.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog and EPSS data is unavailable, so its exploitation likelihood cannot be quantified. Based on the description, the attack can be executed by a normal customer who submits an underpaid transaction through the PayPal Data Transfer return. The attacker would not need technical skills beyond initiating a purchase. Once exploited, the affected site suffers from monetary loss and potential customer trust erosion, but it does not provide code execution or privilege escalation. The lack of a publicly available exploit does not mitigate the seriousness of the potential financial impact. Since there is no official workaround from the CNA, the recommended mitigations focus on patching or disabling the vulnerable feature to stop the logic flaw from being triggered.
OpenCVE Enrichment