CVE-2026-16990 - Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
CVE ID :CVE-2026-16990
Published : Aug. 12, 2026, 12:17 p.m. | 1 hour, 10 minutes ago
Description :The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 12, 2026, 12:17 p.m. | 1 hour, 10 minutes ago
Description :The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...