Impact
Postiz is an AI social media scheduling tool that, prior to version 2.21.8, fails to verify Nowpayments IPN callback authenticity against the payment provider’s shared secret and reads the target subscription identifier from the untrusted request body, enabling a low‑privileged account to grant any organization a lifetime PRO subscription without payment. This flaw reflects a lack of credential verification (CWE‑345) and an incorrectly protected privileged operation (CWE‑639). Based on the description, it is inferred that the attacker can trigger the vulnerability by sending a crafted IPN callback containing a target subscription identifier to the exposed endpoint.
Affected Systems
Vendors: GitroomHQ’s Postiz application, versions prior to 2.21.8 are affected. All installations of Postiz 2.20.x and earlier that accept Nowpayments IPN callbacks without authentication are vulnerable until the 2.21.8 or later release.
Risk and Exploitability
The CVSS score of 7.7 indicates a medium‑high severity. The EPSS score is below 1%, suggesting that exploitation is currently unlikely, and the item is not listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw allows direct privilege escalation through a web‑hook that can be triggered from any network with write access to the IPN endpoint, and that an attacker with low privileges can immediately trigger the exploit if the callback endpoint is publicly reachable. Verification of the Nowpayments shared secret or IP whitelisting would mitigate the risk.
OpenCVE Enrichment