What is CVE-2026-16990?
This vulnerability exists in the 'Payment Button for PayPal' WordPress plugin (up to version 1.2.3.44). The plugin fails to enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order for an arbitrary lower amount. It is recommended to update the plugin to the latest patched version immediately.
Azərbaycanca: Bu zəiflik "Payment Button for PayPal" WordPress plaginində (1.2.3.44-ə qədər versiyalar) aşkarlanıb. Plagin server tərəfində satıcının təyin etdiyi qiyməti yoxlamır və müştəri tərəfindən göndərilən ödəniş məbləğinə etibar edir, bu da autentifikasiya olunmamış hücumçulara real PayPal sifarişi yaradaraq istədikləri aşağı məbləği ödəməyə imkan verir. Təhlükəsizlik üçün plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What does the CVE-2026-16990 vulnerability in the "Payment Button for PayPal" plugin allow?
This vulnerability allows unauthenticated attackers to create a real PayPal order for an arbitrary lower amount because the plugin fails to enforce the merchant-configured price server-side and trusts a client-supplied payment amount.
What action is recommended to protect against CVE-2026-16990?
It is recommended to update the plugin to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.