CVE-2026-16990: Unknown Payment Button For PayPal
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.
Affected products
- Unknown Payment Button For PayPal: up to and including 1.2.3.44
Published 2026-08-12. Last modified 2026-08-26.