CVE · High

CVE-2026-9284 — WooCommerce PayPal Payments [woocommerce-paypal-payments] < 4.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9284 WooCommerce PayPal Payments [woocommerce-paypal-payments] < 4.0.2 Missing Authorization High 8.2 < 4.0.2 4.0.2 2026-05-22

CVE-2026-9284

The WooCommerce PayPal Payments plugin for WordPress has a security flaw that allows attackers to manipulate and access sensitive order information without proper authorization. Specifically, the plugin's WC-AJAX endpoints for creating and retrieving orders do not properly verify the user's permissions, enabling attackers to create PayPal orders for any WooCommerce order and extract sensitive details such as customer information and shipping data. This vulnerability can be exploited by unauthenticated attackers to disrupt the payment process and steal sensitive order information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.