What is CVE-2026-17008?
The Quick Paypal Payments WordPress plugin up to version 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order as paid based solely on an order-token match, allowing a buyer to pay an arbitrary small amount and have a full-price order marked as paid.
Azərbaycanca: Quick Paypal Payments WordPress plugin (5.7.50-ə qədər versiyalar) PayPal IPN handler-da ödənilən məbləği, alıcını və ödəniş statusunu yoxlamır. Yalnız order-token uyğunluğuna əsaslanaraq sifarişi ödənilmiş kimi qeyd etdiyi üçün təcavüzkar kiçik bir məbləğ ödəyərək tam qiymətli sifarişi ödənilmiş kimi göstərə bilər.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
How can an attacker exploiting this vulnerability have a full-price order marked as paid?
An attacker can capture the order-token and pay a small amount. Since the plugin does not verify the paid amount, receiver, or payment status, it marks the order as paid based solely on an order-token match.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.