AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16990

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Payment Button for PayPal WordPress plugin allows unauthenticated attackers to manipulate the payment amount by trusting client-supplied values instead of enforcing server-side checks. This vulnerability could lead to financial loss for merchants as attackers can create PayPal orders for arbitrary lower amounts. WordPress site administrators using this plugin should prioritize applying updates or implementing mitigations to prevent exploitation.

CVE
CVE-2026-16990
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.