
PayPal and WordPress expert .
- or -
Post a project like this- Posted:
- Proposals: 62
- Remote
- #4478981
- OPPORTUNITY
- Open for Proposals



Description
I'm looking for a PayPal and WordPress expert to help investigate an issue on my website.
My site is www.mammypi.com/shop, and I sell multiple products through my WordPress shop. Recently, I've noticed something unusual. One specific product has been receiving a large number of orders paid through PayPal, while the rest of the products are not seeing the same activity.
What’s concerning is that the addresses on these orders are marked as “Unconfirmed” in PayPal, and all of them appear to be coming from the UK. Because of this pattern, I’m worried these may not be legitimate or authorised purchases.
I do not want to accept payments from people who may not have knowingly purchased the product, so I’d like someone experienced to properly investigate what’s happening.
Here’s what I need help with:
• Review my WordPress shop and PayPal integration
• Investigate why this particular product is receiving these orders
• Check for possible bot activity, payment misuse, or checkout vulnerabilities
• Confirm whether the PayPal integration is working correctly
• Fix the issue and implement safeguards to prevent it from happening again
Ideally, you’ll have experience with WordPress, WooCommerce, and PayPal payment integrations, as well as troubleshooting unusual payment behaviour.
If you’ve handled similar cases before, please let me know how you would approach diagnosing and fixing this.
Thanks so much, and I look forward to hearing from you.
Hilda A.
100% (5)New Proposal
Login to your account and send a proposal now to get this project.
Log inClarification Board Ask a Question
-

Before I begin, I need a few key details to confirm the attack pattern and implement the right fix:
Order Origin: In WooCommerce, do these suspicious orders show “Unknown” under Order Source?
REST API Activity: Are you seeing requests to /wp-json/wc/store/products?orderby=price in your server logs?
Payment Method: Is “PayPal Advanced Card Processing” enabled in your WooCommerce settings?
Security Plugins: Are you using Cloudflare, reCAPTCHA, or Wordfence?
Email Pattern: Do the buyer emails look fake (e.g., random numbers in Gmail addresses)?
AVS/CVV: In PayPal, are these transactions showing “N” for AVS or CVV match?
Recent Changes: Did anything change on the site just before this spike started?
These questions will help me determine if this is a REST API bot attack—and stop it without blocking real customers.
If you need someone who treats fraud prevention like a system, not just a plugin, I’m ready to help.