CVE-2026-11964: WordPress User Registration Plugin PayPal Webhook Bypass
ID: b9b3ff44-0fd0-5c90-8108-8e8a820d5173
STIX ID: report--b9b3ff44-0fd0-5c90-8108-8e8a820d5173
Feed Name: CosmicBytez Labs
A PayPal webhook signature verification bypass (CVE-2026-11964, CVSS 6.5) affects all versions of the WordPress plugin 'User Registration & Membership' prior to 5.2.2, allowing unauthenticated attackers who can reach the webhook URL to submit forged payment notifications and obtain premium membership access without paying; the issue was disclosed June 22, 2026 and patched in version 5.2.2, with recommended remediation steps including immediate update, account audits, credential rotation, and reviewing PayPal logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
