CVE-2026-17605: Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaidpaymentformelement function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17605?
CVE-2026-17605 has a medium severity rating of 6.6.
How do I fix CVE-2026-17605?
To fix CVE-2026-17605, update the GetPaid plugin to a version later than 2.8.56.
What is the impact of CVE-2026-17605?
CVE-2026-17605 allows authenticated attackers with administrator-level access to perform Local File Inclusion.
Which versions are affected by CVE-2026-17605?
CVE-2026-17605 affects all versions of the GetPaid plugin for WordPress up to and including 2.8.56.
Is CVE-2026-17605 exploitable remotely?
CVE-2026-17605 is not directly exploitable remotely, as it requires authenticated administrator access.