Payment Processing Flaw in WooCommerce Plugin from WooCommerce
CVE-2026-15211

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-15211?

The Subscriptions for WooCommerce plugin prior to version 2.0.1 fails to adequately validate the payment amounts during the order completion process. This vulnerability allows an unauthenticated attacker, particularly in scenarios where guest checkout is enabled, to exploit the system by substituting their own uncaptured PayPal order token. Consequently, the system incorrectly marks the order as paid when the capture status is marked as COMPLETED. This significant flaw in payment processing can lead to unauthorized payments without the buyer having to fulfill their financial obligations.

Affected Version(s)

Subscriptions for WooCommerce 0 < 2.0.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro Pinho
WPScan
.