PT-2026-67127 · WordPress · Getpaid

·

CVE-2026-17605

·

Published

2026-08-01

·

Updated

2026-08-03

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Payment forms, Buy now buttons, and Invoicing System | GetPaid versions prior to 2.8.57
Description The plugin is susceptible to Local File Inclusion, a condition where an application includes files from the local file system without proper validation. This occurs through the getpaid payment form element() function. Authenticated attackers with administrator-level access or higher can include and execute arbitrary .php files on the server, enabling the execution of any PHP code contained within those files. This flaw can be leveraged to bypass access controls, retrieve sensitive data, or achieve remote code execution if .php files can be uploaded to the server.
Recommendations Update to a version newer than 2.8.56. As a temporary mitigation, restrict administrator-level access to the plugin functions until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17605

Affected Products

Getpaid