CVE-2025-12752

MEDIUM

PayPal WordPress Plugin <1.1.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-345
Status published
Products (1)
scottpaterson/Subscriptions & Memberships for PayPal < 1.1.7
Published Nov 22, 2025
Tracked Since Feb 18, 2026