Impact
The ProfileGrid WordPress plugin prior to version 5.9.9.7 fails to verify PayPal IPN notifications before assigning paid group memberships. An attacker can forge an IPN message, causing the plugin to grant paid group privileges to any target user without a legitimate payment. This flaw enables unauthenticated manipulation of user privileges and potentially grants access to paid content or features reserved for group members. The weakness is identified as an Improper Access Control (CWE-284).
Affected Systems
WordPress installations that have the ProfileGrid plugin at any version earlier than 5.9.9.7 are affected. Any user account on these sites can be promoted to paid membership by sending a forged PayPal IPN, thereby exposing the site’s premium content to unauthorized users.
Risk and Exploitability
The vulnerability has a medium CVSS score of 6.5 and an EPSS score of less than 1%, indicating a low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is remote and unauthenticated, inferred from the description that an attacker only needs to send a crafted PayPal IPN message to trigger the plugin’s membership grant logic without legitimate verification.
OpenCVE Enrichment