CVE-2026-92400: Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Payment Gateway for PayPal on WooCommerce WordPress pluginto a version that resolves this vulnerability.Fixed in 9.2.1
Event History
Frequently Asked Questions
Which stores are exposed to this issue?
Stores using the Payment Gateway for PayPal on WooCommerce WordPress plugin before version 9.2.1 are affected. The issue concerns order-completion handling for incoming payment notifications.
What does an attacker need to exploit it?
An attacker does not need authentication. They need to control a genuine transaction in a PayPal payment sandbox and use it to cause their own order to be marked as paid.
What validation is missing?
The affected plugin does not confirm that the payment notification came from the payment environment configured by the store. It also does not verify that the payment was made to the store's own merchant account before completing the order.
How can administrators check for exposure?
Check the installed version of the Payment Gateway for PayPal on WooCommerce plugin. Versions earlier than 9.2.1 are affected.