{"id":"CVE-2026-107636","summary":"pH7Builder before 18.5.1 Payment Bypass via Payment Module MainController","details":"pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features.","modified":"2026-10-10T02:47:23.464822357Z","published":"2026-10-08T14:10:34.269Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-472"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107636.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107636.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107636"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ph7builder-before-18.5.1-payment-bypass-via-payment-module-maincontroller"},{"type":"FIX","url":"https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/5218d017491fc855c0c788bd020e2376efdee76e"},{"type":"PACKAGE","url":"https://github.com/pH7Software/pH7-Social-Dating-CMS"},{"type":"ARTICLE","url":"https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.5.0/_protected/app/system/modules/payment/controllers/MainController.php#L274-L380"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ph7software/ph7-social-dating-cms","events":[{"introduced":"0"},{"fixed":"6c3208be5a14f2260f1823c5ce53cce2a6d904eb"},{"fixed":"5218d017491fc855c0c788bd020e2376efdee76e"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"18.5.1"}]}}],"versions":["v18.5.0","v18.4.1","v18.4.0","v18.3.0","v18.2.0","v18.1.0","v17.9.2","17.9.2-beta.2","17.9.2-beta.1","v17.9.1-beta.1","v17.9.1","v17.9.0","18.0.0-beta.2","18.0.0-beta.1","17.2.0","17.2.0-rc.2","17.2.0-rc.1","17.2.0-beta.1","17.1.8","17.1.8.beta.2","17.1.8.beta.1","17.1.2","17.1.0","17.0.1","17.0.0","v17.0.0","17.0.0-beta.3","v17.0.0-beta.2","17.0.0-beta.2","16.5.0.beta.1","16.3.2","16.3.0-beta.1","16.3.0","16.2.2","16.2.0-beta.1","16.2.0","16.1.0","16.1.0-beta.1","16.0.2-beta.1","16.0.0","16.0.0-rc.3","16.0.0-rc.2","16.0.0-rc.1","16.0.0-beta.2","16.0.0-beta.1","15.4.0","15.4.0-beta.2","15.4.0-beta.1","15.3.0","15.3.0-rc.3","15.3.0-rc.1","15.2.0","15.1.8","15.1.7","15.1.6","15.1.0","15.1.0-rc2","15.1.0-rc","15.1.0-beta","15.0.0","15.0.0-rc","15.0.0-beta2","15.0.0-beta1","14.9.0","14.9.0-rc2","14.9.0-rc","14.8.9","14.8.8","14.8.8-rc2","14.8.8-rc","14.8.0","14.7.0","14.3.6","14.3.4-rc","14.3.0","14.0.0","14.0.0-rc3","14.0.0-rc2","14.0.0-rc","12.9.9","12.9.8","untagged-de05a9b7f66bb64ad418","12.9.0","12.6.1","12.6.5","12.5.9","12.3.5","12.6.0","12.3.0","12.1.2","12.1.0","12.0.0","10.2.0","10.0.8","8.0.6","8.0.4","8.0.3","8.0.2","7.1.3","7.0.01","7.0.0","6.0.13","6.0.9","6.0.1","6.0.0","5.0.0","4.0.0","3.1.0","3.0.0","2.0.9","2.0.4","1.4.2","1.4.1","1.4.0","1.3.9","1.3.8","1.3.7","1.3.6","1.3.5","1.3.0","1.2.9","1.2.8","1.2.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107636.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}