A Security researcher has discovered a new flaw in the two-factor authentication process implemented by PayPal to protect its users. The flaw resides in the login process when a user is prompted to connect his eBay account to his PayPal account. The company said it planned to fix it, but in time he is writing the flaw is still exploitable. PayPal said it plans to fix the flaw in June, but the researcher is writing that the flaw still remains exploitable in time for the next few months. An attacker could access the account and send money exploiting the flaw.”]
Source: http://securityaffairs.co/wordpress/27368/hacking/paypal-two-factor-authentication.html