Impact
A vulnerability in the payment processing logic of pH7Builder allows registered, low‑privileged members to submit crafted request data that bypasses the normal plan and amount validation. By setting parameters such as item_number, cart_order_id, or the PayPal custom field, or by submitting incomplete PayPal IPN notifications, an attacker can force the system to grant the most expensive membership tier and its associated paid features. This flaw is an Improper Authorization weakness, as it permits unauthorized elevation of privileges and acquisition of premium content.
Affected Systems
The affected system is the pH7Builder (pH7 Social Dating CMS) application from ph7software. Versions prior to 18.5.1 are vulnerable; users running 18.5.0 or earlier are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote web-based, inferred from the description, as an attacker who can submit crafted HTTP requests to the payment module can trigger the bypass without needing elevated credentials or code execution. If an attacker successfully manipulates the payment data, they gain unauthorized access to paid membership tiers, resulting in potential loss of confidentiality of premium features and integrity of membership control.
OpenCVE Enrichment