AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17008

MEDIUM · CVSS 5.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Quick Paypal Payments plugin for WordPress versions up to 5.7.50 is vulnerable due to insufficient validation in its PayPal IPN handler, allowing attackers to exploit order-token matching to mark full-price orders as paid with arbitrary low payment amounts. This could lead to significant financial losses for merchants as unauthorized transactions may go undetected. WordPress site administrators using this plugin should prioritize updating to mitigate potential exploitation.

CVE
CVE-2026-17008
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%
WordPress

Original NVD Description

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid.