{
 "id": "WPSEC-2026-0704",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0704/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0704/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0704/index.md",
 "title": "Braintree for WooCommerce Payment Gateway <= 3.12.0 - Unauthenticated Payment Verification Bypass via Unvalidated Payment Method Nonce Type",
 "description": "The PayPal Enterprise Payments (formerly Braintree) for WooCommerce plugin for WordPress is vulnerable to payment verification bypass via the PayPal, Venmo, local payment, Apple Pay and Google Pay checkout flows in all versions up to, and including, 3.12.0. This is due to the plugin not checking with Braintree that the payment method behind a submitted payment method nonce is the type the selected gateway expects. This makes it possible for unauthenticated attackers to pay with a regular card nonce through these flows, skipping the 3D Secure and card security code checks the store owner enabled for card payments.",
 "plugin": {
  "slug": "woocommerce-gateway-paypal-powered-by-braintree",
  "name": "Braintree for WooCommerce Payment Gateway",
  "full_name": "PayPal Enterprise Payments (formerly Braintree) for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woocommerce-gateway-paypal-powered-by-braintree/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woocommerce-gateway-paypal-powered-by-braintree"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-345"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.12.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.12.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.12.1",
 "remediation": "Update to 3.12.1 or later.",
 "fix_released": "2026-10-08T18:50:35+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:22.667439+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0704/",
  "https://plugins.svn.wordpress.org/woocommerce-gateway-paypal-powered-by-braintree/tags/3.12.1/",
  "https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woocommerce-gateway-paypal-powered-by-braintree",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}