
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2428 is an Insufficient Verification of Data Authenticity vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting all versions up to and including 6.1.17. The flaw allows unauthenticated attackers to send forged PayPal IPN (Instant Payment Notification) messages to the plugin's publicly accessible IPN endpoint, causing unpaid form submissions to be marked as paid and triggering post-payment automation such as email delivery, access grants, and digital product fulfillment. It was published on February 27, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). In PayPalSettings.php, the disable_ipn_verification option defaults to 'yes', meaning PayPal IPN signature verification is disabled out of the box. Because no cryptographic or origin validation is performed on incoming IPN POST requests, any unauthenticated network attacker can craft a forged IPN payload and submit it directly to the plugin's publicly reachable IPN endpoint. No authentication, special privileges, or user interaction is required, making the attack vector entirely network-based with low complexity (Wordfence, ENISA EUVD).
Successful exploitation allows an attacker to fraudulently obtain goods, services, or digital content without completing actual payment. Specifically, an attacker can trigger post-payment automation workflows — including confirmation emails, membership/access grants, and digital product delivery — for any form submission without paying. While confidentiality and availability are not directly impacted (CVSS C:N/A:N), the integrity impact is rated High, as payment records and fulfillment states are falsified. This can result in direct financial loss for site operators and unauthorized access to premium content or services (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.018%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and zero authentication requirement make it straightforward to exploit by any attacker who can identify a vulnerable WordPress site running the plugin (Wordfence, Red Hat CVE).
/wp-content/plugins/fluentformpro/), or tools like WPScan.admin-ajax.php action or a dedicated REST endpoint configured by the plugin for PayPal callbacks).payment_status=Completed, a valid-looking txn_id, and the item_number or custom field corresponding to a target form submission ID.disable_ipn_verification defaults to 'yes', the plugin skips PayPal's verification step and processes the notification as authentic.admin-ajax.php?action=fluentform_ipn_listener or equivalent) originating from IP addresses not associated with PayPal's known IP ranges (64.4.240.0/21, 66.211.168.0/22, 173.0.80.0/20, 216.113.188.0/22).payment_status=Completed from non-PayPal source IPs; repeated IPN submissions for the same txn_id or item_number.wp_fluentform_submissions or equivalent tables) without a corresponding verified IPN transaction ID in PayPal.Update the plugin to a version released after 6.1.17 that addresses this vulnerability — consult the Fluent Forms changelog for the patched release. As an immediate workaround, site administrators should manually enable PayPal IPN verification in the plugin's PayPal settings by setting disable_ipn_verification to 'no' if the plugin UI exposes this option. Additionally, restrict access to the IPN endpoint at the web server or WAF level to only allow inbound connections from PayPal's known IP ranges. Monitoring PayPal merchant account transactions against plugin payment records is also recommended to detect any fraudulent fulfillment (Wordfence, Fluent Forms Changelog).
The vulnerability was reported by Wordfence and received standard automated distribution across vulnerability aggregators and social media channels including Mastodon (RedPacketSecurity) and Bluesky shortly after publication. No notable independent researcher commentary or significant media coverage beyond routine CVE syndication has been identified (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."