Description
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
Published: 2026-08-10
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Accept PayPal & Stripe with Subscriptions for WooCommerce plugin allows a user to pay less than the order total and still have the order recorded as fully paid because the plugin does not compare the amount received in PayPal’s Data Transfer return against the expected amount. This logical flaw enables a payment bypass that can be abused to obtain goods or services without paying the correct amount, leading to financial loss and erosion of customer trust. The weakness reflects improper authorization (CWE‑284).

Affected Systems

WordPress sites that have installed the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin version 3.1.0 or earlier are the only systems impacted. No other plugins or WordPress components are currently known to be affected.

Risk and Exploitability

The CVSS score is 3.7, indicating moderate severity, and the EPSS estimate is below 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation can be carried out by any ordinary customer who initiates a purchase through PayPal, taking advantage of the Data Transfer feature. No special technical skills are required, but the attacker can extract a financial benefit by receiving goods or services for less than the expected payment. The impact is limited to monetary loss and reputational damage; the vulnerability does not grant code execution or privilege escalation.

Generated by OpenCVE AI on August 13, 2026 at 11:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin to the latest version that validates the amount received on payment return
  • If a patch is not immediately available, disable the PayPal Data Transfer (PDT) feature in the plugin settings while a fix is awaited
  • Add a server‑side check that compares the amount received against the order total before marking the order as paid and monitor for anomalous underpayments

Generated by OpenCVE AI on August 13, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-640

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-640

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
Title Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-11T20:18:14.012Z

Reserved: 2026-07-24T10:12:43.610Z

Link: CVE-2026-17016

cve-icon Vulnrichment

Updated: 2026-08-11T20:18:10.614Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:48.710

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-17016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:30:16Z

Weaknesses