Unauthenticated Broken Access Control in WooCommerce Payment Gateway for PayPal
CVE-2026-59547
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-59547?
The Payment Gateway for PayPal on WooCommerce versions up to 9.1.4 is susceptible to unauthenticated broken access control vulnerabilities. This weakness can enable an unauthorized attacker to exploit the system, potentially allowing them to gain access to sensitive functionalities of the PayPal integration without appropriate authentication. Site administrators and users should be aware of this vulnerability and ensure they are using the latest secure version of the plugin.
Affected Version(s)
Payment Gateway for PayPal on WooCommerce <= 9.1.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program