Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-08-10

CVE-2026-17016 - Stripe With Subscriptions For Woocommerce Plugin

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal Data Transfer feature is enabled.

PLUGIN Stripe With Subscriptions For Woocommerce

CVE-2026-17016

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17012 - Stripe With Subscriptions For Woocommerce Plugin

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full amount to their own PayPal account instead of the merchant's.

PLUGIN Stripe With Subscriptions For Woocommerce

CVE-2026-17012

UNKNOWN CVSS 0.0 2026-08-10
Scroll to top