You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
This CVE record is not being prioritized for NVD enrichment efforts due to resource or other concerns.
Description
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester's session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers' order payment flows and exfiltrate sensitive order details (payer information, shipping data) by creating a PayPal order for a victim's WC order and then retrieving the PayPal order data.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: plugin de WooCommerce PayPal Payments para WordPress, Description: El plugin WooCommerce PayPal Payments para WordPress es vulnerable a la manipulación no autorizada de pedidos y a la revelación de información debido a la falta de comprobaciones de autorización en los endpoints WC-AJAX 'ppc-create-order' y 'ppc-get-order' en todas las versiones hasta la 4.0.1, inclusive. El endpoint 'ppc-create-order' acepta un ID de pedido de WooCommerce arbitrario en el contexto 'pay-now' sin validar la propiedad del pedido, lo que permite a los atacantes crear pedidos de PayPal para cualquier pedido de WC y escribir metadatos de PayPal en él. El endpoint 'ppc-get-order' devuelve los detalles completos del pedido de PayPal para cualquier ID de pedido de PayPal sin vincularse a la sesión del solicitante. Esto hace posible que atacantes no autenticados encadenen estos endpoints para manipular los flujos de pago de pedidos de otros clientes y exfiltrar detalles sensibles del pedido (información del pagador, datos de envío) creando un pedido de PayPal para el pedido de WC de una víctima y luego recuperando los datos del pedido de PayPal.
New CVE Received from Wordfence5/23/2026 1:16:34 AM
Action
Type
Old Value
New Value
Added
Description
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it. The `ppc-get-order` endpoint returns full PayPal order details for any PayPal order ID without binding to the requester's session. This makes it possible for unauthenticated attackers to chain these endpoints to manipulate other customers' order payment flows and exfiltrate sensitive order details (payer information, shipping data) by creating a PayPal order for a victim's WC order and then retrieving the PayPal order data.