CVE-2026-17008
Received Received - Intake

Unauthorized Payment Completion in Quick Paypal Payments WordPress Plugin

Vulnerability report for CVE-2026-17008, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: WPScan

Description

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quick_paypal_payments plugin to 5.7.51 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Quick PayPal Payments WordPress plugin versions 5.7.50 and below. It allows an unauthenticated attacker to bypass payment verification by exploiting the PayPal IPN handler. The plugin fails to validate the paid amount, receiver, or payment status, instead relying solely on an order-token match to mark an order as paid.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Quick PayPal Payments plugin version 5.7.50 or below. Inspect the PayPal IPN handler for improper validation of payment details. Look for orders marked as paid despite receiving small arbitrary amounts.

Impact Analysis

An attacker can pay a small arbitrary amount and still have a full-price order marked as completed. This could lead to financial losses for the website owner as orders are processed without receiving the full payment.

Compliance Impact

This vulnerability could lead to unauthorized transactions being marked as paid, potentially violating financial transaction integrity requirements in standards like GDPR (data protection) and HIPAA (security). Unverified payments may result in improper handling of financial data, raising compliance risks for organizations processing payments through the affected plugin.

Mitigation Strategies

Immediately update the Quick PayPal Payments plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Monitor order payments for discrepancies between paid amounts and order totals.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17008. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart