Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation
2025-11-21 18:49
Md. Moniruzzaman Prodhan (NomanProdhan)Strategic Overview
StatusPatched in 1.1.8
Affected PluginSubscriptions & Memberships for PayPal
Affected Version
<= 1.1.7CVSS5.3Medium
CVE
CVE-2025-12752Vulnerability Overview
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.
Technical Analysis
REMEDIATION: Update to version 1.1.8, or a newer patched version --- IDENTIFIER: CWE-345 (Insufficient Verification of Data Authenticity) The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C