CVE-2026-12688
EUVD-2026-4848924.07.2026, 07:16
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.