PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17012 WooCommerce CVE debrief

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.

Vendor
WooCommerce
Product
Accept PayPal & Stripe with Subscriptions for WooCommerce
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-10
Advisory published
2026-08-10
Advisory updated
2026-08-10

Who should care

Merchants using the Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin, as well as their security teams and vulnerability management teams, should be aware of this vulnerability and take steps to verify their PayPal account configurations and monitor transactions for discrepancies. Additionally, operators of WooCommerce platforms and security service providers may also be impacted by this vulnerability and should review their exposure and implement compensating controls as needed. Security teams responsible for vulnerability management and incident response should prioritize this vulnerability and ensure that affected systems are remediated or mitigated promptly. Platform operators and security service providers should also review their asset inventory and ensure that all affected systems are identified and remediated. This vulnerability could potentially allow unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's, which could lead to financial losses and reputational damage for merchants. Therefore, it is essential for merchants and their security teams to take immediate action to verify their PayPal account configurations and monitor transactions for discrepancies. Security teams should also review their monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls, such as additional monitoring and verification of transactions, should be implemented while remediation is scheduled and verified. Affected product deployments should be confirmed to exist in managed environments and an owner should be assigned for follow-up. The official CVE record and NVD entry should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Rollback change windows and source tracking should also be considered to ensure that the vulnerability is fully remediated and that any potential backdoors or vulnerabilities re

Technical summary

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid. This vulnerability could allow unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's. Merchants using the plugin should verify their PayPal account configurations and monitor transactions for discrepancies.

Defensive priority

Merchants using the Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin should verify their PayPal account configurations and monitor transactions for discrepancies.

Recommended defensive actions

  • Verify PayPal account configurations
  • Monitor transactions for discrepancies
  • Consider updating to a patched version of the plugin
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid. This could potentially allow unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's. Defenders should verify PayPal account configurations and monitor transactions for discrepancies.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:48.600Z and has not been modified since then.