CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15211

mediumCVSS 5.9covered by 1 sourcefirst seen 2026-08-07
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price.

⚡ Watch CVE-2026-15211

Get an email if CVE-2026-15211 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-15211

CVE.org record

Embed the live status

CVE-2026-15211 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15211 status](https://www.csirts.com/badge/CVE-2026-15211)](https://www.csirts.com/cve/CVE-2026-15211)