Description
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it.
Exploitation requires the attacker to already know the payment provider's identifier for the victim's stored method, which the Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not expose.
Published: 2026-09-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized payment method hijacking
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an Insecure Direct Object Reference flaw in the Payment Plugins for PayPal WooCommerce WordPress plugin prior to version 2.0.26. Because the plugin does not verify that a stored payment method belongs to the user attaching it, an authenticated user can bind another customer's stored card to their own account. Once bound, the attacker may charge the account or delete the payment method, resulting in unauthorized financial activity and privacy exposure. The weakness is represented by CWE‑863 as a failure to enforce identity and authorization checks.

Affected Systems

Affected systems include any WordPress installation that has the Payment Plugins for PayPal WooCommerce plugin installed with a version earlier than 2.0.26. The vendor’s product is distributed as a plugin for WordPress and does not impose additional server or hosting requirements; any site hosting the plugin is potentially vulnerable.

Risk and Exploitability

Exploitation requires an authenticated session and the attacker’s prior knowledge of the victim’s payment provider identifier, which the plugin does not expose by default. Since the flaw is limited to authenticated users, the likely attack vector is through legitimate user accounts with permissions such as subscriber. The CVSS score of 5.9 reflects moderate impact, and the EPSS score of < 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Overall risk remains significant for sites that have not applied the latest patch or implemented stricter role controls.

Generated by OpenCVE AI on September 9, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PayPal WooCommerce plugin to version 2.0.26 or later, where the payment method ownership check is enforced.
  • Restrict the ability to assign stored payment methods to administrators only, removing this capability for subscriber roles.
  • Modify the plugin configuration or custom code to prevent exposure of internal identifiers for stored payment methods, limiting the attacker’s ability to guess payment provider IDs.
  • Audit recent transactions for signs of unauthorized charges and notify affected users if suspicious activity is detected.

Generated by OpenCVE AI on September 9, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires the attacker to already know the payment provider's identifier for the victim's stored method, which the Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not expose.
Title Payment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment Method Assignment via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:39:21.517Z

Reserved: 2026-08-26T09:19:38.732Z

Link: CVE-2026-80341

cve-icon Vulnrichment

Updated: 2026-09-09T15:33:41.561Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:16.860

Modified: 2026-09-09T16:17:09.623

Link: CVE-2026-80341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:00:12Z

Weaknesses