CVE-2026-82215
Received Received - Intake

Unauthenticated Payment Status Manipulation in PayPay for WooCommerce

Vulnerability report for CVE-2026-82215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: WPScan

Description

The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-01
AI Q&A
2026-09-11
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wc_paypay_gateway plugin From 0.5 (inc) to 0.9.3 (inc)
paypay woocommerce From 0.5 (inc) to 0.9.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the PayPay for WooCommerce WordPress plugin versions 0.5 to 0.9.3. It allows unauthenticated attackers who know the store's merchant identifier to manipulate order statuses by sending unverified payment notifications. Attackers can mark orders as paid, cancel them, or fail them without proper authentication.

Detection Guidance

Check if the WC PayPay Gateway plugin version is between 0.5 and 0.9.3. Inspect webhook notifications for the PayPay plugin to verify if they are properly authenticated before processing order status changes.

Impact Analysis

This vulnerability can lead to financial losses as attackers may mark unpaid orders as paid or cancel legitimate orders. It can also disrupt business operations by failing valid transactions. Since it requires knowing the merchant identifier, businesses with exposed identifiers are at higher risk.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized changes to order statuses, potentially leading to incorrect financial records or unauthorized access to payment data. Unverified payment notifications may result in improper handling of personal or financial information, violating data integrity and security requirements under these regulations.

Mitigation Strategies

Update the WC PayPay Gateway plugin to the latest version if available. If no update exists, disable the plugin temporarily or restrict access to the webhook endpoint to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82215. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart