CVE-2026-17016: Unknown Accept PayPal & Stripe With Subscriptions For Woocommerce
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.
Affected products
- Unknown Accept PayPal & Stripe With Subscriptions For Woocommerce: up to and including 3.1.0
Published 2026-08-10. Last modified 2026-08-26.