Back to CVE List

CVE-2026-12688

Vulnerability Description

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ProfileGrid

External References

Discussion (0)

Add Comment

No comments yet. Be the first!