What is CVE-2026-17012?
CVE-2026-17012 is a critical vulnerability in the "Accept PayPal & Stripe with Subscriptions for WooCommerce" WordPress plugin up to version 3.1.0. The flaw allows unauthenticated buyers to complete a WooCommerce order without legitimate payment by exploiting the lack of verification that the PayPal account receiving the payment matches the merchant's configured account. Users must immediately update the plugin to the latest patched version.
Azərbaycanca: CVE-2026-17012, 3.1.0 versiyasına qədər "Accept PayPal & Stripe with Subscriptions for WooCommerce" WordPress plaginində aşkar edilmiş kritik zəiflikdir. Zəiflik, ödənişi alan PayPal hesabının mağazanın konfiqurasiya edilmiş hesabı ilə uyğunluğunun yoxlanılmaması səbəbindən, autentifikasiya olunmamış alıcıya WooCommerce sifarişini ödənişsiz tamamlamağa imkan verir. Plagin istifadəçiləri dərhal ən son versiyaya yeniləməli və ya təhlükəsizlik yamasını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
How can a WooCommerce order be completed without payment by exploiting CVE-2026-17012?
The flaw allows unauthenticated buyers to complete an order without legitimate payment by exploiting the lack of verification that the PayPal account receiving the payment matches the merchant's configured account.
Which version of the "Accept PayPal & Stripe with Subscriptions for WooCommerce" plugin should I avoid to protect against CVE-2026-17012?
Versions up to 3.1.0 are affected, so users must immediately update to the latest version or apply the security patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.