Braintree for WooCommerce Payment Gateway <= 3.12.0 - Unauthenticated 3D Secure and Card Security Code Verification Bypass via Client-Controlled Checkout Fields
- ID
- WPSEC-2026-0705
- Plugin
- PayPal Enterprise Payments (formerly Braintree) for WooCommerce (woocommerce-gateway-paypal-powered-by-braintree)
- Affected
- all versions before 3.12.1
- Remediation
- Update to 3.12.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-602
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- Braintree for WooCommerce Payment Gateway on WPSec AttackSurface
- Fix released
- Published
Description
The PayPal Enterprise Payments (formerly Braintree) for WooCommerce plugin for WordPress is vulnerable to 3D Secure and Card Security Code verification bypass via the credit card checkout in all versions up to, and including, 3.12.0. This is due to the credit card gateway relying on client-posted hidden fields ('wc-braintree-credit-card-3d-secure-enabled' and '-3d-secure-verified') to decide whether the server checks 3D Secure and whether 3D Secure is required on the transaction. The gateway also trusted posted wallet data when marking saved cards as Apple Pay or Google Pay cards, which exempts them from 3D Secure, and it did not require a security code nonce for saved cards. This makes it possible for unauthenticated attackers to complete card payments without the 3D Secure and card security code checks the store owner enabled, for example when paying with stolen card details.
References
- https://wpsec.com/vuln/WPSEC-2026-0705/
- https://plugins.svn.wordpress.org/woocommerce-gateway-paypal-powered-by-braintree/tags/3.12.1/
- https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS