CVE-2026-17016: Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress pluginto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17016?
CVE-2026-17016 has a risk score of 65.
How do I fix CVE-2026-17016?
To fix CVE-2026-17016, upgrade to the latest version of the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin.
What is the impact of CVE-2026-17016?
CVE-2026-17016 allows customers to bypass payment validation, potentially leading to underpayment for orders.
Which version of the plugin is affected by CVE-2026-17016?
CVE-2026-17016 affects the Accept PayPal & Stripe with Subscriptions for WooCommerce plugin version 3.1.0 and earlier.
Is there a workaround for CVE-2026-17016?
A temporary workaround for CVE-2026-17016 is to disable the PayPal Payment method until the plugin is updated.