๐Ÿ” CVE Alert

CVE-2026-12688

UNKNOWN 0.0

ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.

Vendor unknown
Product profilegrid
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown profilegrid

Be the first to know when new unknown vulnerabilities affecting unknown profilegrid are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ProfileGrid
0 < 5.9.9.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b62a2c10-78da-4a7d-a6e1-f50ebf0763db/

Credits

Revanth Hari Narayana Matte WPScan