Description
pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features.
Published: 2026-10-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Payment Validation Bypass
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the payment processing logic of pH7Builder allows registered, low‑privileged members to submit crafted request data that bypasses the normal plan and amount validation. By setting parameters such as item_number, cart_order_id, or the PayPal custom field, or by submitting incomplete PayPal IPN notifications, an attacker can force the system to grant the most expensive membership tier and its associated paid features. This flaw is an Improper Authorization weakness, as it permits unauthorized elevation of privileges and acquisition of premium content.

Affected Systems

The affected system is the pH7Builder (pH7 Social Dating CMS) application from ph7software. Versions prior to 18.5.1 are vulnerable; users running 18.5.0 or earlier are at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote web-based, inferred from the description, as an attacker who can submit crafted HTTP requests to the payment module can trigger the bypass without needing elevated credentials or code execution. If an attacker successfully manipulates the payment data, they gain unauthorized access to paid membership tiers, resulting in potential loss of confidentiality of premium features and integrity of membership control.

Generated by OpenCVE AI on October 8, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pH7Builder to version 18.5.1 or later, which includes the payment validation fix.
  • Until the upgrade can be applied, restrict or disable low‑privileged members from accessing or initiating payment requests to prevent unauthorized tier elevation.
  • Ensure that all plan, amount, and PayPal custom fields are validated server‑side: reject any values that do not match a defined product tier and verify that PayPal IPN notifications are fully processed before assigning new membership levels.

Generated by OpenCVE AI on October 8, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features.
Title pH7Builder before 18.5.1 Payment Bypass via Payment Module MainController
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:52:19.191Z

Reserved: 2026-10-08T14:05:59.689Z

Link: CVE-2026-107636

cve-icon Vulnrichment

Updated: 2026-10-08T16:00:34.516Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:46.543

Modified: 2026-10-08T18:17:25.180

Link: CVE-2026-107636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:04Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter