Missing Authorization Vulnerability in Payment Plugins for PayPal WooCommerce
CVE-2026-39643
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-39643?
A missing authorization issue exists in the Payment Plugins for PayPal WooCommerce plugin, which could be exploited due to incorrectly configured access control security levels. This vulnerability impacts versions up to 2.0.13, allowing potential attackers to bypass necessary permissions, compromising the security of transactions and sensitive user data.
Affected Version(s)
Payment Plugins for PayPal WooCommerce 0 <= 2.0.13