Payment Plugins for PayPal WooCommerce
Payment Plugins for PayPal WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Payment Plugins for PayPal WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Ba Khanh. Payment Plugins for PayPal WooCommerce is installed on roughly 80,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.3.
CVE-2026-39643Payment Plugins for PayPal WooCommerce <= 2.0.13 - Missing Authorization
Read the full analysisVulnerability Records

Payment Plugins for PayPal WooCommerce
Author
Payment Plugins
woocommerceDeveloped exclusively between Payment Plugins and PayPal, PayPal for WooCommerce integrates with PayPal’s newest API’s. To boost conversion rates, you can offer PayPal, Pay Later, Venmo, or credit cards on your site. There are many supported features so merchants can configure the plugin to suit their business needs. In order to process payments online, you will need a PayPal Business Account. Supports Fastlane Advanced Credit and Debit Card Payments (ACDC) Apple Pay Google Pay WooCommerce Subscriptions WooCommerce Pre-Orders WooCommerce Blocks WooFunnels AeroCheckout and Upsell Integrates with Payment Plugins for Stripe WooCommerce CheckoutWC Payment Plugins is an official PayPal Partner
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C