CVE-2026-82215: WC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified Webhook
The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker does not need authentication, but must know the store's merchant identifier. They can then send unverified payment notifications that cause arbitrary orders to be marked paid, cancelled, or failed.
Which plugin versions are affected?
The affected version range is 0.5 through 0.9.3 of the Payment Gateway PayPay for WooCommerce WordPress plugin.
How can I determine whether my store may have been affected?
Review order histories for unexpected transitions to paid, cancelled, or failed states, particularly where the state change does not correspond to a legitimate payment notification. Stores using an affected plugin version should treat unauthorized webhook-driven order changes as possible indicators.