---
id: CVE-2026-82215
title: >-
  The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3
  does not verify the authenticity of the payment notifications it receives
  before acting on them, allowing unauthenticated attackers who know the store's
  mercha…
summary: >-
  The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3
  does not verify the authenticity of the payment notifications it receives
  before acting on them, allowing unauthenticated attackers who know the store's
  mercha…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-345
product: Payment Gateway PayPay for WooCommerce
affected:
  - payment_gateway_paypay_for_woocommerce >= 0.5 <= 0.9.3
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82215'
references:
  - url: 'https://wpscan.com/vulnerability/c7703a51-9d5d-4483-b214-7249701ee9ff/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-11T12:05:53.830567Z'
ingestedAt: '2026-09-11T16:45:47.922Z'
epss: 0.0016
epssPercentile: 0.0453
---

## Overview

The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
