PatchSiren cyber security CVE debrief
CVE-2026-17012 WooCommerce CVE debrief
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.
- Vendor
- WooCommerce
- Product
- Accept PayPal & Stripe with Subscriptions for WooCommerce
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-10
Who should care
Merchants using the Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin, as well as their security teams and vulnerability management teams, should be aware of this vulnerability and take steps to verify their PayPal account configurations and monitor transactions for discrepancies. Additionally, operators of WooCommerce platforms and security service providers may also be impacted by this vulnerability and should review their exposure and implement compensating controls as needed. Security teams responsible for vulnerability management and incident response should prioritize this vulnerability and ensure that affected systems are remediated or mitigated promptly. Platform operators and security service providers should also review their asset inventory and ensure that all affected systems are identified and remediated. This vulnerability could potentially allow unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's, which could lead to financial losses and reputational damage for merchants. Therefore, it is essential for merchants and their security teams to take immediate action to verify their PayPal account configurations and monitor transactions for discrepancies. Security teams should also review their monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls, such as additional monitoring and verification of transactions, should be implemented while remediation is scheduled and verified. Affected product deployments should be confirmed to exist in managed environments and an owner should be assigned for follow-up. The official CVE record and NVD entry should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Rollback change windows and source tracking should also be considered to ensure that the vulnerability is fully remediated and that any potential backdoors or vulnerabilities re
Technical summary
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid. This vulnerability could allow unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's. Merchants using the plugin should verify their PayPal account configurations and monitor transactions for discrepancies.
Defensive priority
Merchants using the Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin should verify their PayPal account configurations and monitor transactions for discrepancies.
Recommended defensive actions
- Verify PayPal account configurations
- Monitor transactions for discrepancies
- Consider updating to a patched version of the plugin
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid. This could potentially allow unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's. Defenders should verify PayPal account configurations and monitor transactions for discrepancies.
Official resources
-
CVE-2026-17012 CVE record
CVE.org
-
CVE-2026-17012 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:48.600Z and has not been modified since then.