Known Vulnerabilities for Merchant Sdk by Paypal
Listed below are 1 of the newest known vulnerabilities associated with "Merchant Sdk" by "Paypal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-47741 json | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-17012 json | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal ... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-16990 json | The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side an... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-16620 json | The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for pr... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-15657 json | A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant cr... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-15152 json | The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made ... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-15150 json | The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matche... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-15148 json | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-15045 json | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the ... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-14936 json | The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's... | Not Provided | 2026-08-06 | 2026-08-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Paypal | Merchant Sdk | - |