The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.
History

Mon, 24 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Scottpaterson
Scottpaterson subscriptions & Memberships For Paypal
Wordpress
Wordpress wordpress
Vendors & Products Scottpaterson
Scottpaterson subscriptions & Memberships For Paypal
Wordpress
Wordpress wordpress

Sat, 22 Nov 2025 07:45:00 +0000

Type Values Removed Values Added
Description The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.
Title Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-11-22T07:29:19.967Z

Updated: 2025-11-24T19:32:47.365Z

Reserved: 2025-11-05T15:10:49.804Z

Link: CVE-2025-12752

cve-icon Vulnrichment

Updated: 2025-11-24T19:32:42.517Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-22T08:15:42.953

Modified: 2025-11-25T22:16:42.557

Link: CVE-2025-12752

cve-icon Redhat

No data.