Impact
The vulnerability arises because the plugin does not confirm that the PayPal order ID attached to a payment request actually belongs to the corresponding WooCommerce order. As a result, an unauthenticated attacker can trigger the capture of a buyer’s approved but uncaptured PayPal payment on an order belonging to the attacker’s account. This creates a weakness that allows neither authorization decisions nor resource access to be reliably validated, aligned with CWE‑639.
Affected Systems
Any installation of Payment Plugins for PayPal WooCommerce earlier than version 2.0.27 is affected. The product is a WordPress plugin that integrates WooCommerce with PayPal, and the issue applies to all sites running the vulnerable versions. No specific sub‑version is mentioned, so the vulnerability is considered present in all releases before 2.0.27.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact. Because the EPSS score is not available, the exploitation probability is unknown, but the vulnerability does not require authentication, raising the likelihood that the flaw could be abused if an attacker discovers or guesses a valid PayPal order ID belonging to another user. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited, but the ease of triggering an unauthorized payment capture means the risk to merchants is significant.
OpenCVE Enrichment