CVE-2026-107636Medium· 6.5▾ SunlitpH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107637Medium· 4.3pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories
CVE-2026-107638Medium· 6.8pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits
CVE-2026-107363Medium· 6.1In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token
CVE-2026-105322Medium· 5.3The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
CVE-2026-90987Medium· 5.3The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
CVE-2026-91020Medium· 5.3The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to…