PT-2026-69358 · WordPress · Accept Paypal & Stripe With Subscriptions

CVE-2026-17016

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin versions prior to 3.1.1
Description The plugin fails to validate the actual amount paid against the order total within its PayPal Data Transfer return handler. This flaw allows a customer to pay an amount lower than the order total, yet the system still marks the order as fully paid, provided the PayPal Data Transfer feature is enabled.
Recommendations Update the plugin to version 3.1.1 or later. As a temporary mitigation, disable the PayPal Data Transfer feature.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17016

Affected Products

Accept Paypal & Stripe With Subscriptions