logo

CVE-2026-11964: WordPress User Registration Plugin PayPal Webhook Bypass

ID: b9b3ff44-0fd0-5c90-8108-8e8a820d5173

STIX ID: report--b9b3ff44-0fd0-5c90-8108-8e8a820d5173

Feed Name: CosmicBytez Labs

Threat Score
55/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

A PayPal webhook signature verification bypass (CVE-2026-11964, CVSS 6.5) affects all versions of the WordPress plugin 'User Registration & Membership' prior to 5.2.2, allowing unauthenticated attackers who can reach the webhook URL to submit forged payment notifications and obtain premium membership access without paying; the issue was disclosed June 22, 2026 and patched in version 5.2.2, with recommended remediation steps including immediate update, account audits, credential rotation, and reviewing PayPal logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.