CVE-2026-12688
Vulnerability Description
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ProfileGrid
Discussion (0)
Add Comment
No comments yet. Be the first!