CVE-2026-16990
Received Received - Intake

Payment Button for PayPal WordPress Plugin Price Manipulation

Vulnerability report for CVE-2026-16990, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: WPScan

Description

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
paypal payment_button_for_paypal to 1.2.3.44 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Payment Button for PayPal WordPress plugin versions 1.2.3.44 and below. It allows unauthenticated attackers to manipulate the payment amount by sending client-supplied data that the plugin does not validate server-side. This means attackers can create PayPal orders for arbitrary lower amounts without needing authentication.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Payment Button for PayPal plugin version 1.2.3.44 or below. Inspect network traffic for PayPal payment requests where the amount parameter is manipulated. Look for unauthorized PayPal orders with incorrect amounts.

Impact Analysis

If you use the affected plugin, attackers could exploit this to pay less than the intended amount for products or services. Merchants may lose revenue as orders are processed for incorrect lower prices. Since no authentication is required, the risk of exploitation is high.

Compliance Impact

This vulnerability could lead to non-compliance with financial and data protection regulations such as GDPR or HIPAA by enabling unauthorized transactions. If exploited, it may result in improper handling of payment data, financial discrepancies, or unauthorized access to sensitive information, violating regulatory requirements for secure transactions and data integrity.

Mitigation Strategies

Immediately update the Payment Button for PayPal plugin to the latest version if available. If no update exists, consider disabling the plugin until a fix is released. Monitor PayPal orders for suspicious lower amounts and review server logs for unauthorized payment requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16990. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart