SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59547

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

An unauthenticated broken access control vulnerability exists in the Payment Gateway for PayPal on WooCommerce versions 9.1.4 and earlier, allowing unauthorized users to manipulate payment processes. This could lead to unauthorized transactions or data exposure, posing a significant risk to e-commerce operations. Merchants using affected versions of WooCommerce should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-59547
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.