← Back to search

CVE-2026-92400

5.3 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows unauthenticated users to mark their own orders as paid by using a genuine transaction from a payment sandbox they control, bypassing order verification.
Exploitability
Exploitation requires access to a payment sandbox environment and knowledge of the plugin version. It is moderately difficult due to the need for sandbox control but feasible with proper setup.
Blast radius
If exploited, it could lead to unauthorized changes in user orders, potentially affecting financial records and customer trust.
Prioritized remediation
Update the Payment Gateway for PayPal on WooCommerce WordPress plugin to version 9.2.1 or later to ensure order verification is properly enforced.
auth-bypasswebwoocommercepaypal

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-345

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.