Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-7441 Details

Description

cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]

Affected Products

ProductVersions
woocommerce paypal checkout payment gateway
1.6.8

CPE

  • cpe:2.3:a:woocommerce:paypal_checkout_payment_gateway:1.6.8:*:*:*:*:wordpress:*:*

Remediation

  • No remediation found in references.

Change History

27 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-7441
NVD Published Date:
Mar 21, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-7441 Details - Not Deferred