WordPress Payment Gateway for PayPal on WooCommerce是WordPress基金会开源的一款在线支付处理插件。 WordPress Payment Gateway for PayPal on WooCommerce 9.2.1之前版本存在输入验证错误漏洞,该漏洞源于在PayPal返回处理程序中未验证支付是否实际成功,可能导致未经身份验证的攻击者将任意订单标记为已支付而无需付款。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Payment Gateway for PayPal on WooCommerce | < 9.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Payment Gateway for PayPal on WooCommerce | 0 ~ 9.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16747 | 6.5 MEDIUM | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions |
| CVE-2026-15045 | 6.5 MEDIUM | Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalid |
| CVE-2026-17008 | 5.3 MEDIUM | Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN |
| CVE-2026-16990 | 5.3 MEDIUM | Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation |
| CVE-2026-15213 | 5.3 MEDIUM | Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callba |
| CVE-2026-18044 | 3.7 LOW | Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Si |
| CVE-2026-18789 | Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes | |
| CVE-2026-17013 | WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart | |
| CVE-2026-18962 | WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authori | |
| CVE-2026-19052 | ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog C | |
| CVE-2026-19073 | Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disc | |
| CVE-2026-19217 | Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget | |
| CVE-2026-19050 | ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate | |
| CVE-2026-18057 | Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection | |
| CVE-2026-18049 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo | |
| CVE-2026-18366 | Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator | |
| CVE-2026-18230 | WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter | |
| CVE-2026-18391 | WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection | |
| CVE-2026-18048 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzi | |
| CVE-2026-18046 | Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update |
Showing top 20 of 44 CVEs. View all on vendor page → →
No comments yet