Payment Gateway PayPay for WooCommerce
Payment Gateway PayPay for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Insufficient Verification Of Data Authenticity, behind 1 of the records (100%).
The one issue recorded for Payment Gateway PayPay for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Pedro Pinho. Payment Gateway PayPay for WooCommerce is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-82215Payment Gateway PayPay for WooCommerce 0.5 - 0.9.3 - Unauthenticated Payment Bypass
Read the full analysisVulnerability Records

Payment Gateway PayPay for WooCommerce
Author
Hiroaki Miyashita
woocommerceThe Payment Gateway PayPay for WooCommerce plugin adds the functionality to take PayPay payments on your store of WooCommerce. About PayPay PayPay is barcode based payment services in Japan. In order to start PayPay payments, you need to create a PayPay developer account. PayPay for Developers In order to make the mode Real, you have to purchase the authentication key at the following site. WordPress Market External services This plugin connects to the PayPay Open Payment API to create and manage payments. Order amounts, merchant-generated payment identifiers, and any optional order descriptions or items configured by the merchant may be sent to PayPay when a payment is created or managed. This service is provided by PayPay Corporation under its terms and privacy policy. When an administrator saves the gateway settings, the plugin connects to WordPress Market to validate the optional Authentication Key used to enable Real mode. The site’s domain and the entered Authentication Key are sent for this purpose. This service is provided by e-t net Inc. under the WordPress Market terms and privacy policy. Known Issues / Bugs Nothing. Uninstall Deactivate the plugin That’s it! 🙂
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C