CVE-2026-17016
Received Received - Intake

PayPal Data Transfer Underpayment in WooCommerce Subscriptions

Vulnerability report for CVE-2026-17016, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
woocommerce accept_paypal_stripe_with_subscriptions 3.1.0
woocommerce accept_paypal_stripe_with_subscriptions to 3.1.0 (inc)
woocommerce restore_paypal_standard to 3.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin. It fails to check if a customer paid the full order amount when using PayPal Data Transfer. This lets customers pay less than required while the system still marks the order as fully paid.

Detection Guidance

Check if the 'Restore PayPal Standard for WooCommerce' plugin version 3.1.0 or below is installed. Review PayPal Data Transfer (PDT) logs for transactions where the paid amount does not match the order total.

Impact Analysis

This could lead to financial losses for merchants using the plugin. Customers might exploit it to pay less than the actual order total while the system incorrectly processes the order as complete.

Compliance Impact

This vulnerability could lead to non-compliance with financial and data protection regulations by allowing underpayment of orders while marking them as fully paid. This may result in incorrect financial records, potential fraud, and violations of standards requiring accurate transaction validation.

Mitigation Strategies

Disable the PayPal Data Transfer (PDT) feature in the plugin settings. Update the plugin to the latest version if an update becomes available. Monitor transactions for underpayments and verify order statuses manually.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17016. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart