WordPress security by component
Payment Gateway PayPay for WooCommerce
Payment Gateway PayPay for WooCommerce (payment-gateway-paypay-for-woocommerce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.9.
Plugin slug:
payment-gateway-paypay-for-woocommerceLatest vulnerability
CVE-2026-82215: PayPay for WooCommerce accepts unauthenticated forged payment notices
Payment Gateway PayPay for WooCommerce versions 0.5 through 0.9.3 act on payment notifications without verifying their authenticity. An unauthenticated attacker who knows the store's merchant identifier can mark arbitrary orders paid or change them to cancelled or failed. The authoritative export does not identify the callback route, notification fields, or signature-validation function.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-82215
PayPay for WooCommerce accepts unauthenticated forged payment notices
Payment Gateway PayPay for WooCommerce versions 0.5 through 0.9.3 act on payment notifications without verifying their authenticity. An unauthenticated attacker who knows the store's merchant identifier can mark arbitrary orders paid or change them to cancelled or failed. The authoritative export does not identify the callback route, notification fields, or signature-validation function.
|
See mitigation notes |
CVE5.9
NVDPending
|