What is CVE-2026-12688?
CVE-2026-12688 is a critical vulnerability in the ProfileGrid WordPress plugin before version 5.9.9.7, caused by missing verification of PayPal IPN notifications. This allows unauthenticated attackers to forge payment notifications and grant any user paid group membership without making an actual payment. The plugin must be updated to the latest version immediately.
Azərbaycanca: CVE-2026-12688, ProfileGrid WordPress plugin-inin 5.9.9.7-dən əvvəlki versiyalarında PayPal IPN bildirişlərini doğrulamaması səbəbindən yaranan kritik boşluqdur. Bu, autentifikasiya olunmamış hücumçuya saxta ödəniş bildirişi göndərərək istənilən istifadəçini pulsuz şəkildə ödənişli qrup üzvü etməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: PayPal
FAQ2
Which versions of the ProfileGrid plugin are affected by CVE-2026-12688?
CVE-2026-12688 affects all versions of the ProfileGrid WordPress plugin prior to version 5.9.9.7.
What does the CVE-2026-12688 vulnerability allow an unauthenticated attacker to do?
The CVE-2026-12688 vulnerability allows an unauthenticated attacker to forge PayPal IPN payment notifications, granting any user paid group membership without making an actual payment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.