PT-2026-22290 · WordPress · Fluent Forms Pro Add On Pack For Wordpress
Prickly Cactus
·
Published
2026-02-27
·
Updated
2026-03-04
·
CVE-2026-2428
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Forms Pro Add On Pack for WordPress versions through 6.1.17
Description
The software contains a flaw related to insufficient verification of data authenticity. Specifically, PayPal IPN (Instant Payment Notification) verification is disabled by default, with the
disable ipn verification setting defaulting to 'yes' in the PayPalSettings.php file. This allows unauthenticated attackers to send fraudulent PayPal IPN notifications to the publicly accessible IPN endpoint. Successful exploitation can mark unpaid form submissions as "paid," triggering subsequent post-payment automation, such as emails, access grants, and digital product delivery. The API endpoint involved is the publicly accessible IPN endpoint. The vulnerable parameter is the forged PayPal IPN notification data.Recommendations
Versions prior to 6.1.17 should be updated to address this issue.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluent Forms Pro Add On Pack For Wordpress