CVE-2026-13399 HIGH

CVE-2026-13399: Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order

Vendor Unknown
Product Payment Plugins for PayPal WooCommerce
Published August 6, 2026
Last update August 6, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

Explanation of Vulnerability in Simple Terms

02Summary

A vulnerability in Payment Plugins for PayPal WooCommerce versions before 2.0.20 allows an attacker to modify payment data without authentication. The flaw stems from insufficient input validation on payment processing endpoints. An attacker can intercept or manipulate transaction details during payment processing. Site owners should update immediately to version 2.0.20 or later.

What an attacker can do

03Attacker Capabilities

Modify payment transaction data or amounts without authentication.

Potential impact on your site

04Site Impact

Customers' payment amounts or transaction details could be altered, leading to financial loss or fraud.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published