CVE-2025-12752: Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries that have not actually occurred.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12752?
CVE-2025-12752 has a severity rating that indicates it poses a significant risk due to the potential for an attacker to create fake payments.
How do I fix CVE-2025-12752?
To fix CVE-2025-12752, update the Subscriptions & Memberships for PayPal plugin to version 1.1.8 or later.
What versions are affected by CVE-2025-12752?
CVE-2025-12752 affects all versions of the Subscriptions & Memberships for PayPal plugin up to and including version 1.1.7.
What type of attack does CVE-2025-12752 allow?
CVE-2025-12752 allows an unauthenticated attacker to create fake payment requests due to improper verification of IPN requests.
Who is affected by CVE-2025-12752?
Anyone using versions of the Subscriptions & Memberships for PayPal plugin up to version 1.1.7 on WordPress is affected by CVE-2025-12752.