Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field
medium
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to incl...
- CVSS:
- 6.6
- Affected:
- up to 2.8.56
- Fixed in:
- 2.8.57
- Disclosed:
- Jul 31, 2026
CVE-2026-17605 on NVD →
GetPaid <= 2.8.54 - Unauthenticated Payment Bypass
medium
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 2.8.54. This is due to improper IPN verification. This makes it possible for unauthenticated attackers to bypass payments.
- CVSS:
- 5.3
- Affected:
- up to 2.8.54
- Fixed in:
- 2.8.55
- Disclosed:
- Jul 13, 2026
CVE-2026-12901 on NVD →
Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.49 - Unauthenticated Information Exposure
medium
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.49. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.8.49
- Fixed in:
- 2.8.50
- Disclosed:
- Jun 8, 2026
CVE-2026-49064 on NVD →
GetPaid <= 2.8.11 - Missing Authorization via column_subscription()
medium
The GetPaid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the column_subscription() function in versions up to, and including, 2.8.11. This makes it possible for authenticated attackers, with contributor-level access and above, to access backend pages from the pl...
- CVSS:
- 4.3
- Affected:
- up to 2.8.11
- Fixed in:
- 2.8.12
- Disclosed:
- Aug 28, 2024
CVE-2024-43973 on NVD →
WordPress Payments Plugin | GetPaid <= 2.3.3 - Authenticated Stored Cross-Site Scripting
medium
In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which i...
- CVSS:
- 5.4
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Jun 2, 2021
CVE-2021-24369 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database