CVE-2026-82215
Received Received - Intake

Unauthenticated Payment Status Manipulation in PayPay for WooCommerce

Vulnerability report for CVE-2026-82215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: WPScan

Description

The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wc_paypay_gateway plugin From 0.5 (inc) to 0.9.3 (inc)
paypay woocommerce From 0.5 (inc) to 0.9.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the PayPay for WooCommerce WordPress plugin versions 0.5 to 0.9.3. It allows unauthenticated attackers who know the store's merchant identifier to manipulate order statuses by sending unverified payment notifications. Attackers can mark orders as paid, cancel them, or fail them without proper authentication.

Detection Guidance

Check if the WC PayPay Gateway plugin version is between 0.5 and 0.9.3. Inspect webhook notifications for the PayPay plugin to verify if they are properly authenticated before processing order status changes.

Impact Analysis

This vulnerability can lead to financial losses as attackers may mark unpaid orders as paid or cancel legitimate orders. It can also disrupt business operations by failing valid transactions. Since it requires knowing the merchant identifier, businesses with exposed identifiers are at higher risk.

Mitigation Strategies

Update the WC PayPay Gateway plugin to the latest version if available. If no update exists, disable the plugin temporarily or restrict access to the webhook endpoint to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82215. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart