← WordPress Vulnerabilities
WordPress security by component

Payment Gateway PayPay for WooCommerce

Payment Gateway PayPay for WooCommerce (payment-gateway-paypay-for-woocommerce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.9.

Plugin slug: payment-gateway-paypay-for-woocommerce

CVE-2026-82215: PayPay for WooCommerce accepts unauthenticated forged payment notices

Payment Gateway PayPay for WooCommerce versions 0.5 through 0.9.3 act on payment notifications without verifying their authenticity. An unauthenticated attacker who knows the store's merchant identifier can mark arbitrary orders paid or change them to cancelled or failed. The authoritative export does not identify the callback route, notification fields, or signature-validation function.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for payment-gateway-paypay-for-woocommerce
Safe version
Sep 11, 2026 CVE-2026-82215
PayPay for WooCommerce accepts unauthenticated forged payment notices
Payment Gateway PayPay for WooCommerce versions 0.5 through 0.9.3 act on payment notifications without verifying their authenticity. An unauthenticated attacker who knows the store's merchant identifier can mark arbitrary orders paid or change them to cancelled or failed. The authoritative export does not identify the callback route, notification fields, or signature-validation function.
See mitigation notes
CVE5.9
NVDPending