Description
pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields.
Published: 2026-10-11
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthenticated API key bypass revealing sensitive user data
Action: Immediate Patch
AI Analysis

Impact

pH7Builder before version 18.6.0 contains a hard‑coded API key in Tool.class.php, a weakness classified as CWE-798. By sending an HTTP request with a spoofed Host header and the value private_api_key=dev772277, an attacker can bypass the API access checks. This allows the retrieval of member emails, IP addresses, phone numbers, and bank account fields without any authentication.

Affected Systems

The vulnerability affects installations of pH7Builder (pH7 Social Dating CMS) from all releases before 18.6.0, including the 18.5.x branch and earlier. Any site running that CMS with the default configuration is susceptible.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the vulnerability is exploitable over the network by directing crafted HTTP requests to the application. With no authentication required and no additional system configuration needed, an attacker can obtain highly sensitive personal data. The EPSS value is not available, but the lack of KEV listing suggests it has not yet been widely exploited in the wild.

Generated by OpenCVE AI on October 11, 2026 at 16:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pH7Builder to version 18.6.0 or later, which removes the hard‑coded API key and its associated bypass.
  • Deploy a web application firewall rule that rejects requests containing a Host header other than the site's canonical domain.
  • Restrict external access to the API endpoints behind an authentication layer or IP‑based firewall to limit exposure if a backup vulnerability exists.

Generated by OpenCVE AI on October 11, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Sun, 11 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields.
Title pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:58:06.784Z

Reserved: 2026-10-11T14:47:11.318Z

Link: CVE-2026-108905

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T15:16:56.803

Modified: 2026-10-11T15:16:56.913

Link: CVE-2026-108905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T17:00:10Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials