CVE-2025-66107: WordPress Subscriptions & Memberships for PayPal plugin <= 1.1.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66107?
CVE-2025-66107 has a medium severity level due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-66107?
To fix CVE-2025-66107, update the Subscriptions & Memberships for PayPal plugin to the latest version that addresses the access control vulnerability.
Which versions are affected by CVE-2025-66107?
CVE-2025-66107 affects versions of the Subscriptions & Memberships for PayPal plugin from the initial release up to and including version 1.1.7.
What type of vulnerability is CVE-2025-66107?
CVE-2025-66107 is a Missing Authorization vulnerability that can lead to exploitation of incorrectly configured access control settings.
Who is the vendor for the product affected by CVE-2025-66107?
The vendor for the affected product is Scott Paterson, and it is also listed under WordPress.