CVE-2026-107636
Deferred Deferred - Pending Action

Payment Validation Bypass in pH7Builder CMS

Vulnerability report for CVE-2026-107636, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ph7software ph7builder 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-472 The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

pH7Builder before version 18.5.1 has a payment validation flaw where registered low-privileged users can bypass payment requirements to obtain premium membership tiers. By manipulating fields like item_number, cart_order_id, or PayPal custom fields, attackers can set their own plan and amount, effectively gaining access to the most expensive membership features without proper payment.

Detection Guidance

To detect this vulnerability, inspect payment logs for incomplete PayPal IPN payments or manipulated fields like item_number, cart_order_id, or PayPal custom fields. Check if low-privileged users have access to premium membership features without proper payment validation. Review MainController.php for session fixation issues and improper payment status handling.

Impact Analysis

If you are a user of pH7Builder, this vulnerability allows attackers with basic access to exploit the system, potentially gaining unauthorized premium features. For administrators, it risks financial loss due to unpaid membership upgrades and undermines trust in the platform's security.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to sensitive user data through premium features. It may violate data protection principles requiring secure access controls and proper authentication.

Mitigation Strategies

Update pH7Builder to version 18.5.1 or later to address the payment validation flaw. Review payment logs for suspicious transactions where low-privileged users gained premium memberships without proper authorization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107636. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart