CVE-2026-92400
5.3 MEDIUMPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows unauthenticated users to mark their own orders as paid by using a genuine transaction from a payment sandbox they control, bypassing order verification.
- Exploitability
- Exploitation requires access to a payment sandbox environment and knowledge of the plugin version. It is moderately difficult due to the need for sandbox control but feasible with proper setup.
- Blast radius
- If exploited, it could lead to unauthorized changes in user orders, potentially affecting financial records and customer trust.
- Prioritized remediation
- Update the Payment Gateway for PayPal on WooCommerce WordPress plugin to version 9.2.1 or later to ensure order verification is properly enforced.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own orders as paid using a genuine transaction from a payment sandbox they control.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-345
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-10050PoC
- MEDIUMCVE-2026-14465
- HIGHCVE-2026-14553
- MEDIUMCVE-2026-14816
- HIGHCVE-2026-15230
- HIGHCVE-2026-15372
- HIGHCVE-2026-15573
Related by shared AI tags and CWE weakness class. Browse the full archive.