What is CVE-2026-16621?
This is a critical flaw in the Payment Gateway for PayPal on WooCommerce WordPress plugin where the PayPal return handler completes orders without verifying successful payment, allowing attackers to manipulate parameters. Affected versions are before 9.2.1; users should immediately update to version 9.2.1 or higher.
Azərbaycanca: Bu, "Payment Gateway for PayPal on WooCommerce" WordPress pluginindəki kritik boşluqdur: ödənişin uğurlu olub-olmadığını yoxlamadan, təcavüzkarın idarə etdiyi parametrlərlə sifarişi tamamlayır. Təsirə məruz qalan versiyalar 9.2.1-dən əvvəlki versiyalardır; istifadəçilər dərhal 9.2.1 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: WooCommerce
FAQ2
Which versions of the "Payment Gateway for PayPal on WooCommerce" plugin are affected by CVE-2026-16621?
All versions prior to 9.2.1 are affected. You must immediately update to version 9.2.1 or higher to mitigate this vulnerability.
How does an attacker complete an order in the CVE-2026-16621 vulnerability?
The attacker exploits the PayPal return handler's failure to verify whether the payment was successful, allowing them to complete the order with parameters they control.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.