CVE-2026-17605: The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the g
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-17605
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-17605 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Payment forms
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-7623: The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is …nvd · 2026-08-01
- mediumCVE-2026-15782: The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz …nvd · 2026-07-21
- mediumCVE-2026-11567: The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on …nvd · 2026-07-14
- mediumCVE-2026-12738: The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnera…nvd · 2026-07-11
- mediumCVE-2025-11977: The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Mu…nvd · 2026-07-10
- highCVE-2026-9253: The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable t…nvd · 2026-07-09
More from NVD Recent CVEs
- mediumCVE-2026-6453: The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to …2026-08-01
- mediumCVE-2026-18435: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18344: The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site …2026-08-01
- mediumCVE-2026-18062: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18059: The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to…2026-08-01