Local File Inclusion Vulnerability in GetPaid Plugin for WordPress
CVE-2026-17605

6.6MEDIUM

What is CVE-2026-17605?

The GetPaid plugin for WordPress is affected by a Local File Inclusion vulnerability that allows authenticated users with administrator-level access to include and execute arbitrary .php files on the server. This flaw resides in the getpaid_payment_form_element function and can be exploited to bypass access controls, obtain sensitive information, or execute malicious code whenever .php files are uploaded. The issue is present in all versions up to and including 2.8.56, thus exposing websites using this plugin to significant security risks.

Affected Version(s)

Payment forms, Buy now buttons, and Invoicing System | GetPaid 0 <= 2.8.56

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.