Payment Validation Vulnerability in pH7 Social Dating CMS by pH7Software
CVE-2026-107636
7.1HIGH
What is CVE-2026-107636?
The pH7 Social Dating CMS by pH7Software prior to version 18.5.1 contains a payment validation vulnerability that allows low-privileged registered users to manipulate client-controlled plan and amount fields. This exploit enables attackers to circumvent standard payment checks, allowing them to acquire any membership tier, including the most expensive one, by using arbitrary values for item_number, cart_order_id, or by submitting incomplete PayPal IPN payments. This flaw highlights a significant weakness in the payment processing module, necessitating prompt attention to ensure user access levels correspond accurately with payment completions.
Affected Version(s)
ph7builder 0 < 18.5.1
ph7builder 18.5.1
