Improper Input Validation in PayPal Payment Button Plugin by WordPress
CVE-2026-16990
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 August 2026
Badges
What is CVE-2026-16990?
The Payment Button for PayPal WordPress plugin prior to version 1.2.3.44 features a significant vulnerability related to improper input validation. This security flaw allows unauthenticated users to manipulate the payment amount by sending a client-supplied payment value that is not properly validated server-side. As a result, attackers can create fraudulent PayPal orders for an amount significantly lower than intended by the merchant, potentially leading to financial losses.
Affected Version(s)
Payment Button for PayPal 0 <= 1.2.3.44
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved