CVE-2026-17012: Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress pluginto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Until the plugin is updated beyond 3.1.0, restrict/monitor checkout/payment completion paths that rely on PayPal so that unauthenticated buyers cannot mark WooCommerce orders as paid without verifying the PayPal receiver account matches the merchant’s configured account.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17012?
The severity of CVE-2026-17012 is rated at 62, indicating a moderate risk level.
How do I fix CVE-2026-17012?
To fix CVE-2026-17012, update the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin to a version greater than 3.1.0.
What does CVE-2026-17012 exploit?
CVE-2026-17012 exploits a vulnerability in the plugin that allows payment bypass by not validating the receiver_email against the configured merchant account.
Who is affected by CVE-2026-17012?
Users of the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin versions up to 3.1.0 are affected by CVE-2026-17012.
What are the potential impacts of CVE-2026-17012?
The potential impacts of CVE-2026-17012 include unauthorized payments being marked as complete, leading to financial losses for merchants.