A recently discovered PayPal issue allows anyone to reveal the last four digits of the payment method, the account balance and recent transactions. This vulnerability was reported to PayPal’s bug bounty program, where it was classified as being out of scope. The issue still exists as of February 25, 2018.
All the attacker needs to know is the e-mail address and phone number linked to the account. The attacker would then visit the Forgot Password page on PayPal’s web site, and enter the e-mail address of the target account. The web site would offer to confirm the credit card number linked to the account, while presenting the credit card type and the last 2 digits of the credit card number. The attacker would then call the customer service number, and try to guess via the interactive voice response system the last four digits of the credit card number. Having the last two digits already at hand, this leaves only 100 combinations to try.
Once the correct combination of the last four digits has been found, the attacker would use the interactive voice response system to retrieve the account balance and the recent transactions.
Read more about it here.