Known Vulnerabilities for Merchant-sdk-php by Paypal
Listed below are 1 of the newest known vulnerabilities associated with "Merchant-sdk-php" by "Paypal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82215 json | The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-77999 json | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-76842 json | The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, s... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-71809 json | Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-19778 json | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-17012 json | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal ... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-16990 json | The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side an... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-16947 json | The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before... | Not Provided | 2026-08-29 | 2026-08-30 |
| CVE-2026-16620 json | The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for pr... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-15657 json | A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant cr... | Not Provided | 2026-07-30 | 2026-07-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Paypal | Merchant-sdk-php | 3.9.1 |