
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16621 is an unauthenticated payment bypass vulnerability in the "Payment Gateway for PayPal on WooCommerce" WordPress plugin affecting all versions before 9.2.1. The flaw allows an unauthenticated attacker to mark arbitrary orders as paid without actually completing payment by manipulating the plugin's PayPal return handler. It was publicly disclosed on August 3, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (WPScan, Github Advisory).
The root cause is insufficient verification of data authenticity (CWE-345) in the plugin's PayPal Advanced return handler. When a user is redirected back from PayPal after a transaction, the plugin reads attacker-controlled URL parameters without performing any server-side verification of payment success, no comparison of the paid amount against the order total, and no check that the order belongs to the requesting user. As a result, an unauthenticated attacker can craft a direct HTTP request to the return handler endpoint with manipulated parameters to trigger order completion even when the gateway verification fails (WPScan, Github Advisory).
Successful exploitation allows an unauthenticated attacker to fraudulently complete arbitrary WooCommerce orders without payment, causing direct financial loss to store operators. The attack has no impact on confidentiality or availability, but integrity is compromised as order status and payment records are falsified. At scale, this vulnerability could be automated to fulfill large numbers of orders across any unpatched WooCommerce store running the affected plugin (WPScan, Github Advisory).
There is currently no public proof-of-concept exploit available; WPScan has indicated a PoC will be published on August 17, 2026, to allow time for users to update. No in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, though the attack is classified as automatable due to its low complexity and lack of authentication requirements (WPScan, Github Advisory).
wc-api, paypal, or return handler endpoints) from IPs that did not originate a legitimate PayPal redirect.Store operators should immediately upgrade the "Payment Gateway for PayPal on WooCommerce" plugin (woo-paypal-gateway) to version 9.2.1 or later, which contains the fix. As a temporary workaround prior to patching, consider disabling the PayPal payment gateway or restricting access to the return handler endpoint. Additionally, cross-reference all recent orders marked as paid against actual PayPal transaction records to identify any fraudulent completions (WPScan, Github Advisory).
The vulnerability was discovered and reported by security researcher Muni Nitish Kumar Yaddala and verified by WPScan. WPScan has intentionally delayed publication of the proof-of-concept until August 17, 2026, to provide a responsible disclosure window for site operators to patch. No significant broader media coverage or notable social media commentary has been identified at this time (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."