# Braintree for WooCommerce Payment Gateway <= 3.12.0 - Unauthenticated 3D Secure and Card Security Code Verification Bypass via Client-Controlled Checkout Fields

- **ID:** WPSEC-2026-0705
- **Plugin:** PayPal Enterprise Payments (formerly Braintree) for WooCommerce (`woocommerce-gateway-paypal-powered-by-braintree`), https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/
- **Affected versions:** all versions before 3.12.1
- **Fixed in:** 3.12.1 (Update to 3.12.1 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-602
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-gateway-paypal-powered-by-braintree
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0705/

## Description

The PayPal Enterprise Payments (formerly Braintree) for WooCommerce plugin for WordPress is vulnerable to 3D Secure and Card Security Code verification bypass via the credit card checkout in all versions up to, and including, 3.12.0. This is due to the credit card gateway relying on client-posted hidden fields ('wc-braintree-credit-card-3d-secure-enabled' and '-3d-secure-verified') to decide whether the server checks 3D Secure and whether 3D Secure is required on the transaction. The gateway also trusted posted wallet data when marking saved cards as Apple Pay or Google Pay cards, which exempts them from 3D Secure, and it did not require a security code nonce for saved cards. This makes it possible for unauthenticated attackers to complete card payments without the 3D Secure and card security code checks the store owner enabled, for example when paying with stolen card details.

## References

- https://wpsec.com/vuln/WPSEC-2026-0705/
- https://plugins.svn.wordpress.org/woocommerce-gateway-paypal-powered-by-braintree/tags/3.12.1/
- https://wordpress.org/plugins/woocommerce-gateway-paypal-powered-by-braintree/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0705/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
