Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation

Strategic Overview

Status
Patched in 1.1.8
Affected Version<= 1.1.7
CVSS5.3Medium
CVECVE-2025-12752
View all Subscriptions & Memberships for PayPal vulnerabilities

Vulnerability Overview

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.

Technical Analysis

REMEDIATION: Update to version 1.1.8, or a newer patched version --- IDENTIFIER: CWE-345 (Insufficient Verification of Data Authenticity) The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C