CVE-2026-16621: Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16621?
The severity of CVE-2026-16621 is medium, rated at 5.3.
How do I fix CVE-2026-16621?
To fix CVE-2026-16621, update the Payment Gateway for PayPal on WooCommerce plugin to version 9.2.1 or later.
What could happen if I am vulnerable to CVE-2026-16621?
If vulnerable to CVE-2026-16621, an attacker could bypass payment verification and complete orders without actual payment.
Which software is affected by CVE-2026-16621?
CVE-2026-16621 affects the Payment Gateway for PayPal on WooCommerce plugin versions prior to 9.2.1.
When was CVE-2026-16621 published?
CVE-2026-16621 was published on August 12, 2026.