Greetings,

Condtions: In version 1.3.8 using PayPal Payments Std

When zencart recieves notification from paypal , either by return PDT or IPN notification (web_accept hack). It is possible for the customer to have filled out a different address on paypal's optional CC page, than what was entered in zencart's profile.

From what I can tell, there is no comparing of the shipping/confirmed address in the TABLE_PAYPAL to the shipping address in the TABLE_ORDERS.

Without manual inspection, it is possible for a fraudster to use a stolen credit card to ship to a different address or even country.