CVE-2026-2428: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2428 is an Insufficient Verification of Data Authenticity vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting all versions up to and including 6.1.17. The flaw allows unauthenticated attackers to send forged PayPal IPN (Instant Payment Notification) messages to the plugin's publicly accessible IPN endpoint, causing unpaid form submissions to be marked as paid and triggering post-payment automation such as email delivery, access grants, and digital product fulfillment. It was published on February 27, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). In PayPalSettings.php, the disable_ipn_verification option defaults to 'yes', meaning PayPal IPN signature verification is disabled out of the box. Because no cryptographic or origin validation is performed on incoming IPN POST requests, any unauthenticated network attacker can craft a forged IPN payload and submit it directly to the plugin's publicly reachable IPN endpoint. No authentication, special privileges, or user interaction is required, making the attack vector entirely network-based with low complexity (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows an attacker to fraudulently obtain goods, services, or digital content without completing actual payment. Specifically, an attacker can trigger post-payment automation workflows — including confirmation emails, membership/access grants, and digital product delivery — for any form submission without paying. While confidentiality and availability are not directly impacted (CVSS C:N/A:N), the integrity impact is rated High, as payment records and fulfillment states are falsified. This can result in direct financial loss for site operators and unauthorized access to premium content or services (Wordfence, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.018%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and zero authentication requirement make it straightforward to exploit by any attacker who can identify a vulnerable WordPress site running the plugin (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Fluent Forms Pro Add On Pack plugin (versions ≤ 6.1.17) using passive techniques such as HTTP response headers, plugin directory enumeration (/wp-content/plugins/fluentformpro/), or tools like WPScan.
  2. Locate the IPN endpoint: Identify the publicly accessible PayPal IPN handler URL registered by the plugin (typically a WordPress admin-ajax.php action or a dedicated REST endpoint configured by the plugin for PayPal callbacks).
  3. Craft a forged IPN payload: Construct a POST request mimicking a legitimate PayPal IPN notification, including fields such as payment_status=Completed, a valid-looking txn_id, and the item_number or custom field corresponding to a target form submission ID.
  4. Submit the forged notification: Send the crafted POST request directly to the IPN endpoint. Because disable_ipn_verification defaults to 'yes', the plugin skips PayPal's verification step and processes the notification as authentic.
  5. Trigger post-payment automation: The plugin marks the targeted form submission as paid and executes configured post-payment actions — delivering digital products, granting access, or sending confirmation emails — without any actual payment having occurred (Wordfence, ENISA EUVD).

Indicators of compromise

  • Network: Unexpected POST requests to the Fluent Forms PayPal IPN endpoint (e.g., admin-ajax.php?action=fluentform_ipn_listener or equivalent) originating from IP addresses not associated with PayPal's known IP ranges (64.4.240.0/21, 66.211.168.0/22, 173.0.80.0/20, 216.113.188.0/22).
  • Logs: WordPress access logs showing IPN endpoint hits with payment_status=Completed from non-PayPal source IPs; repeated IPN submissions for the same txn_id or item_number.
  • Application: Form submissions in the Fluent Forms dashboard marked as "paid" with no corresponding verified PayPal transaction in the PayPal merchant account; post-payment emails or access grants triggered without matching PayPal payment records.
  • Database: Unexpected updates to form entry payment status fields in the WordPress database (wp_fluentform_submissions or equivalent tables) without a corresponding verified IPN transaction ID in PayPal.

Mitigation and workarounds

Update the plugin to a version released after 6.1.17 that addresses this vulnerability — consult the Fluent Forms changelog for the patched release. As an immediate workaround, site administrators should manually enable PayPal IPN verification in the plugin's PayPal settings by setting disable_ipn_verification to 'no' if the plugin UI exposes this option. Additionally, restrict access to the IPN endpoint at the web server or WAF level to only allow inbound connections from PayPal's known IP ranges. Monitoring PayPal merchant account transactions against plugin payment records is also recommended to detect any fraudulent fulfillment (Wordfence, Fluent Forms Changelog).

Community reactions

The vulnerability was reported by Wordfence and received standard automated distribution across vulnerability aggregators and social media channels including Mastodon (RedPacketSecurity) and Bluesky shortly after publication. No notable independent researcher commentary or significant media coverage beyond routine CVE syndication has been identified (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management