CVE-2026-17012: Unknown Accept PayPal & Stripe With Subscriptions For Woocommerce

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.

Affected products

  • Unknown Accept PayPal & Stripe With Subscriptions For Woocommerce: up to and including 3.1.0

Published 2026-08-10. Last modified 2026-08-26.