What is CVE-2026-13399?
This vulnerability allows unauthenticated users to bypass payments via a REST endpoint due to missing authorization checks in the Payment Plugins for PayPal WooCommerce WordPress plugin. Sites running versions prior to 2.0.20 are affected. Immediate update to the latest plugin version is required.
Azərbaycanca: Bu boşluq ödəniş pluginində yetərsiz avtorizasiya yoxlaması səbəbindən autentifikasiya olunmamış istifadəçilərə REST endpoint vasitəsilə ödənişləri yan keçməyə imkan verir. WordPress PayPal WooCommerce plugininin 2.0.20-dən əvvəlki versiyalarını istifadə edən saytlar risk altındadır. Dərhal pluginin ən son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-13399?
This vulnerability affects the Payment Plugins for PayPal WooCommerce WordPress plugin.
To what version should the plugin be updated to protect against CVE-2026-13399?
The plugin should be updated to version 2.0.20 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.