# Braintree for WooCommerce Payment Gateway <= 3.12.0 - Unauthenticated Payment Verification Bypass via Unvalidated Payment Method Nonce Type

- **ID:** WPSEC-2026-0704
- **Plugin:** PayPal Enterprise Payments (formerly Braintree) for WooCommerce (`woocommerce-gateway-paypal-powered-by-braintree`), https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/
- **Affected versions:** all versions before 3.12.1
- **Fixed in:** 3.12.1 (Update to 3.12.1 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-345
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-gateway-paypal-powered-by-braintree
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0704/

## Description

The PayPal Enterprise Payments (formerly Braintree) for WooCommerce plugin for WordPress is vulnerable to payment verification bypass via the PayPal, Venmo, local payment, Apple Pay and Google Pay checkout flows in all versions up to, and including, 3.12.0. This is due to the plugin not checking with Braintree that the payment method behind a submitted payment method nonce is the type the selected gateway expects. This makes it possible for unauthenticated attackers to pay with a regular card nonce through these flows, skipping the 3D Secure and card security code checks the store owner enabled for card payments.

## References

- https://wpsec.com/vuln/WPSEC-2026-0704/
- https://plugins.svn.wordpress.org/woocommerce-gateway-paypal-powered-by-braintree/tags/3.12.1/
- https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0704/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
