VYPR

Subscriptions Memberships For Paypal

by WordPress

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-12752Med0.345.30.00Nov 22, 2025The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.
CVE-2025-66107Med0.345.30.00Nov 21, 2025Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.