CVE-2026-80342: Payment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order ID
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured payment captured against an order of their own.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
WooCommerce stores using Payment Plugins for PayPal WooCommerce versions before 2.0.27 are affected. The issue concerns payment requests that supply a PayPal order ID.
What does an attacker need to exploit it?
An attacker needs another buyer's PayPal payment that has been approved but not yet captured, along with the ability to supply that PayPal order ID in a payment request. No authentication is required.
When does the plugin fail to validate the PayPal order ID?
The plugin does not verify that the supplied PayPal order belongs to the WooCommerce order being paid unless the PayPal order has already been completed. An approved but uncaptured PayPal order is therefore the relevant exposure condition.
What is the available remediation?
Update Payment Plugins for PayPal WooCommerce to version 2.0.27 or later. The affected versions are those before 2.0.27.