CVE-2026-93511
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 23, 2026
Vendor
unknown
Description
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know.