THREAT OPS › Threat News › [NVD] CVE-2026-17605 (MEDIUM 6.6) — The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with admin
[NVD] CVE-2026-17605 (MEDIUM 6.6) — The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with admin
CVE-2026-17605 CVSS: 6.6 MEDIUM Published: 2026-08-01T09:17:01.820
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and exec
Indicators of compromise
- CVE-2026-17605cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17605