CVE-2026-9284
The WooCommerce PayPal Payments plugin for WordPress has a security flaw that allows attackers to manipulate and access sensitive order information without proper authorization. Specifically, the plugin's WC-AJAX endpoints for creating and retrieving orders do not properly verify the user's permissions, enabling attackers to create PayPal orders for any WooCommerce order and extract sensitive details such as customer information and shipping data. This vulnerability can be exploited by unauthenticated attackers to disrupt the payment process and steal sensitive order information.
Based on public CVE data (MITRE/NVD).