{"id":"CVE-2026-92400","published":"2026-09-21T09:17:06.270","lastModified":"2026-09-21T15:17:35.047","description":"The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-345"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/3dcee743-a95d-4233-b78e-8449a6cc8aea/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to mark their own orders as paid by using a genuine transaction from a payment sandbox they control, bypassing order verification.","exploitability":"Exploitation requires access to a payment sandbox environment and knowledge of the plugin version. It is moderately difficult due to the need for sandbox control but feasible with proper setup.","blast_radius":"If exploited, it could lead to unauthorized changes in user orders, potentially affecting financial records and customer trust.","remediation":"Update the Payment Gateway for PayPal on WooCommerce WordPress plugin to version 9.2.1 or later to ensure order verification is properly enforced.","tags":["auth-bypass","web","woocommerce","paypal"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:27:30.401Z"}}