CVE-2026-16621

Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the server-side gateway verification fails, allowing an unauthenticated attacker to mark arbitrary orders as paid without paying.


We have discovered 2,938 live websites that are affected by CVE-2026-16621.

Run a Free Instant Scan




Affected Software

Product  PayPal for WooCommerce
Category WooCommerce Plugins
Vulnerable Domains2,938 live websites (100% of PayPal for WooCommerce install base)
Vulnerable Versions
  • from 0 through 9.2.1
Vulnerable Versions Count127 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-345 Insufficient Verification of Data Authenticity



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Muni Nitish Kumar Yaddala (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16621
United States1,555 websites



Germany283 websites
GB217 websites
France131 websites
Italy112 websites
Australia109 websites
Canada96 websites
Spain63 websites
Cyprus39 websites
Brazil21 websites

Website Distribution by TLD

Number of websites using CVE-2026-16621
.com1,840 websites
.de141 websites
.co.uk140 websites
.org126 websites
.com.au99 websites
.net79 websites
.it77 websites
.ca55 websites
.fr44 websites
.es34 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16621

Top websites that are affected by CVE-2026-16621. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Netherlands*,***
*******.org United States*,***
***********.net United States**,***
************.com United States**,***
*******.com United States**,***
*******.com United States**,***
**********.com United States**,***
*******.com Netherlands**,***
**************.com United States**,***
*************.com United States**,***
See full domain list

FAQ

CVE-2026-16621 is Insufficient Verification of Data Authenticity in PayPal for WooCommerce
A total of 2,938 websites have been identified as vulnerable to CVE-2026-16621, based on global website indexing conducted by WebTechSurvey.
The PayPal for WooCommerce is affected by the CVE-2026-16621 vulnerability.
PayPal for WooCommerce versions up to 9.2.1 are vulnerable to CVE-2026-16621.
CVE-2026-16621 is resolved in version 9.2.1 of PayPal for WooCommerce.