PT-2026-67127 · WordPress · Getpaid
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Payment forms, Buy now buttons, and Invoicing System | GetPaid versions prior to 2.8.57
Description
The plugin is susceptible to Local File Inclusion, a condition where an application includes files from the local file system without proper validation. This occurs through the
getpaid payment form element() function. Authenticated attackers with administrator-level access or higher can include and execute arbitrary .php files on the server, enabling the execution of any PHP code contained within those files. This flaw can be leveraged to bypass access controls, retrieve sensitive data, or achieve remote code execution if .php files can be uploaded to the server.Recommendations
Update to a version newer than 2.8.56.
As a temporary mitigation, restrict administrator-level access to the plugin functions until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getpaid