Payment Validation Vulnerability in pH7 Social Dating CMS by pH7Software
CVE-2026-107636

7.1HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107636?

The pH7 Social Dating CMS by pH7Software prior to version 18.5.1 contains a payment validation vulnerability that allows low-privileged registered users to manipulate client-controlled plan and amount fields. This exploit enables attackers to circumvent standard payment checks, allowing them to acquire any membership tier, including the most expensive one, by using arbitrary values for item_number, cart_order_id, or by submitting incomplete PayPal IPN payments. This flaw highlights a significant weakness in the payment processing module, necessitating prompt attention to ensure user access levels correspond accurately with payment completions.

Affected Version(s)

ph7builder 0 < 18.5.1

ph7builder 18.5.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haluk Baran AKBULUT (CyberMap Group)
.