A vulnerability, which was classified as problematic, has been found in stiofansisland Payment forms, Buy now buttons and and Invoicing System Plugin up to 2.8.56 on WordPress. Impacted is the function getpaid_payment_form_element. This manipulation causes file inclusion.

This vulnerability is registered as CVE-2026-17605. Remote exploitation of the attack is possible. No exploit is available.