PT-2026-97200 · WordPress · Premium Packages

·

CVE-2026-93511

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Premium Packages WordPress plugin versions prior to 7.2.1
Description The plugin fails to verify the signature of webhooks received from PayPal when processing payment and subscription notifications. This allows unauthenticated attackers to forge payment confirmations and subscription-cancellation events for any order, provided they possess the transaction ID. A webhook is an automated message sent from one application to another to notify it about an event.
Recommendations Update the Premium Packages WordPress plugin to version 7.2.1 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93511

Affected Products

Premium Packages