CVE-2026-93511: Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs to know the transaction ID of a target order. No authentication is required to forge payment confirmations or subscription-cancellation events.
Which installations are affected?
Premium Packages installations running a version before 7.2.1 are affected.
What should be prioritized for remediation?
Update Premium Packages to version 7.2.1 or later. Until updated, treat payment and subscription webhook events as untrusted and review affected orders for unexpected payment confirmations or cancellation events.