{"id":"CVE-2025-30152","aliases":["GHSA-hxg4-65p5-9w37"],"url":"https://o3.security/vulnerability/CVE-2025-30152","summary":"Sylius PayPal Plugin has an Order Manipulation Vulnerability after PayPal Checkout","details":"The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart after completing the PayPal Checkout process and payment authorization. If a user initiates a PayPal transaction from a product page or the cart page and then returns to the order summary page, they can still manipulate the cart contents before finalizing the order. As a result, the order amount in Sylius may be higher than the amount actually captured by PayPal, leading to a scenario where merchants deliver products or services without full payment. The issue is fixed in versions: 1.6.2, 1.7.2, 2.0.2 and above.","published":"2025-03-19T15:57:32.445Z","modified":"2026-07-15T01:49:01.425180872Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"sylius/paypal-plugin","fixedVersion":"1.6.2"},{"ecosystem":"Packagist","name":"sylius/paypal-plugin","fixedVersion":"1.7.2"},{"ecosystem":"Packagist","name":"sylius/paypal-plugin","fixedVersion":"2.0.2"}],"fix":{"url":"https://github.com/Sylius/PayPalPlugin/commit/5613df827a6d4fc50862229295976200a68e97aa","label":"Sylius/PayPalPlugin@5613df8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30152.json"},{"type":"ADVISORY","url":"https://github.com/Sylius/PayPalPlugin/security/advisories/GHSA-hxg4-65p5-9w37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30152"},{"type":"FIX","url":"https://github.com/Sylius/PayPalPlugin/commit/5613df827a6d4fc50862229295976200a68e97aa"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:01.425180872Z"}}