Executive brief
The ProfileGrid plugin for WordPress, which manages user profiles and paid memberships, contains a flaw in how it handles payment notifications. An attacker can bypass the payment process by sending a fake notification to the website, tricking the system into granting them or any other user access to paid groups without actually paying. This can lead to loss of revenue and unauthorized access to premium content or community features.
Technical details
The ProfileGrid plugin fails to validate the authenticity of PayPal Instant Payment Notifications (IPN) before processing them. Specifically, the plugin does not verify the notification with PayPal's servers or check if the receiver email matches the configured business address. An unauthenticated attacker can send a crafted POST request to the IPN landing page with forged parameters (such as payment_status=Completed and a custom user/group ID string). This results in the plugin updating user metadata to reflect a successful payment, granting the 'paid' membership status without a valid transaction. The issue is fixed in version 5.9.9.7.
Affected products
- ProfileGrid ProfileGrid < 5.9.9.7
Timeline
- 2026-07-03: disclosed: Public disclosure via WPScan
- 2026-07-24: advisory: NVD publication date