PT-2026-97200 · WordPress · Premium Packages
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Premium Packages WordPress plugin versions prior to 7.2.1
Description
The plugin fails to verify the signature of webhooks received from PayPal when processing payment and subscription notifications. This allows unauthenticated attackers to forge payment confirmations and subscription-cancellation events for any order, provided they possess the transaction ID. A webhook is an automated message sent from one application to another to notify it about an event.
Recommendations
Update the Premium Packages WordPress plugin to version 7.2.1 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Premium Packages