All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-16990
MEDIUMpublished 2026-08-12 12:17 UTC · 15 hours ago · modified 2026-08-12 13:17 UTC
5.3
CVSS / 10
// description
The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount.