Unauthenticated Broken Access Control in WooCommerce Payment Gateway for PayPal
CVE-2026-59547

7.5HIGH

What is CVE-2026-59547?

The Payment Gateway for PayPal on WooCommerce versions up to 9.1.4 is susceptible to unauthenticated broken access control vulnerabilities. This weakness can enable an unauthorized attacker to exploit the system, potentially allowing them to gain access to sensitive functionalities of the PayPal integration without appropriate authentication. Site administrators and users should be aware of this vulnerability and ensure they are using the latest secure version of the plugin.

Affected Version(s)

Payment Gateway for PayPal on WooCommerce <= 9.1.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.