WooCommerce Vulnerabilities and Affected Products
Vulnerabilities associated with WooCommerce PayPal Payments.
Products
Clear product- AutomateWoo5 vulnerabilities
- WooCommerce Stripe Payment Gateway5 vulnerabilities
- woocommerce_customers_manager5 vulnerabilities
- woocommerce4 vulnerabilities
- Product Vendors3 vulnerabilities
- Shipping Multiple Addresses3 vulnerabilities
- WooCommerce PayPal Payments3 vulnerabilities
- Product Add-Ons2 vulnerabilities
- WooCommerce Bookings2 vulnerabilities
- WooCommerce Box Office2 vulnerabilities
- WooCommerce Brands2 vulnerabilities
- WooCommerce Follow-Up Emails (AutomateWoo)2 vulnerabilities
- WooCommerce Pre-Orders2 vulnerabilities
- WooCommerce Square2 vulnerabilities
- box_office1 vulnerability
- Bulk Stock Management1 vulnerability
- Canada Post Shipping Method1 vulnerability
- checkout_field_editor1 vulnerability
- Composite Products1 vulnerability
- dropshipping1 vulnerability
- GoCardless1 vulnerability
- Google for WooCommerce1 vulnerability
- help_scout1 vulnerability
- Order Delivery Date Pro1 vulnerability
- persian-woocommerce1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-14073MEDIUM | WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information DisclosureThe WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to obtain sensitive order information including order keys, which can then be leveraged to access full customer billing details (name, … CWE-639Aug 1, 2026 | CVSS5.3v3.1 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9284HIGH | WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information DisclosureThe WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ownership, allowing attackers to create PayPal orders for any WC order and write PayPal metadata to it… CWE-862May 23, 2026 | CVSS8.2v3.1 | EPSS0.401% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35917MEDIUM | WordPress WooCommerce PayPal Payments Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. CWE-352Jun 22, 2023 | CVSS4.3v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |