Payment Processing Flaw in Quick Paypal Payments Plugin by WordPress
CVE-2026-17008
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 12 August 2026
Badges
What is CVE-2026-17008?
The Quick Paypal Payments WordPress plugin versions prior to 5.7.50 contains a security weakness in its PayPal IPN handler. This vulnerability allows an attacker to exploit the payment confirmation process by matching order tokens without validating key transaction details such as the paid amount, receiver, or payment status. Consequently, it's possible for a buyer to make a minimal payment for a full-price order, effectively marking the transaction as paid without legitimate financial processing. This exposes sellers to potential revenue loss and undermines the integrity of the payment system.
Affected Version(s)
Quick Paypal Payments 0 <= 5.7.50
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved