CVE-2026-17016: Unknown Accept PayPal & Stripe With Subscriptions For Woocommerce

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.

Affected products

  • Unknown Accept PayPal & Stripe With Subscriptions For Woocommerce: up to and including 3.1.0

Published 2026-08-10. Last modified 2026-08-26.