Braintree for WooCommerce Payment Gateway <= 3.12.0 - Unauthenticated 3D Secure and Card Security Code Verification Bypass via Client-Controlled Checkout Fields

Low 3.7 CWE-602Fixed in 3.12.1
ID
WPSEC-2026-0705
Plugin
PayPal Enterprise Payments (formerly Braintree) for WooCommerce (woocommerce-gateway-paypal-powered-by-braintree)
Affected
all versions before 3.12.1
Remediation
Update to 3.12.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-602
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
Braintree for WooCommerce Payment Gateway on WPSec AttackSurface
Fix released
Published

Description

The PayPal Enterprise Payments (formerly Braintree) for WooCommerce plugin for WordPress is vulnerable to 3D Secure and Card Security Code verification bypass via the credit card checkout in all versions up to, and including, 3.12.0. This is due to the credit card gateway relying on client-posted hidden fields ('wc-braintree-credit-card-3d-secure-enabled' and '-3d-secure-verified') to decide whether the server checks 3D Secure and whether 3D Secure is required on the transaction. The gateway also trusted posted wallet data when marking saved cards as Apple Pay or Google Pay cards, which exempts them from 3D Secure, and it did not require a security code nonce for saved cards. This makes it possible for unauthenticated attackers to complete card payments without the 3D Secure and card security code checks the store owner enabled, for example when paying with stolen card details.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0