Back to overview

CVE-2026-12688

Description
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.

Metadata

CVE ID
CVE-2026-12688
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-19 08:40 UTC
Published
2026-07-24 06:00 UTC
Last updated
2026-07-24 06:00 UTC
Vendor / Product
Unknown / ProfileGrid
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown ProfileGrid 0 < 5.9.9.7
Weakness (CWE)
CWESourceDescription
cna CWE-284 Improper Access Control
Back to overview