CVE-2026-93511
Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know.
| Vendor | unknown |
| Product | premium packages |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown premium packages
Be the first to know when new unknown vulnerabilities affecting unknown premium packages are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Premium Packages
7.0.0 < 7.2.1
References
Credits
Farid Narimanov WPScan