CVE-2026-16990: Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16990?
The severity of CVE-2026-16990 is classified as medium with a score of 5.3.
How do I fix CVE-2026-16990?
To fix CVE-2026-16990, update the Payment Button for PayPal WordPress plugin to the latest version that addresses this vulnerability.
What kind of attacks can occur due to CVE-2026-16990?
CVE-2026-16990 allows unauthenticated attackers to manipulate the payment amount, creating fraudulent PayPal orders for lower amounts.
What is affected by CVE-2026-16990?
CVE-2026-16990 affects the Payment Button for PayPal WordPress plugin versions up to 1.2.3.44.
Is authentication required to exploit CVE-2026-16990?
No, CVE-2026-16990 can be exploited by unauthenticated attackers.