CVE-2017-17777: Paid To Read Script Project Paid To Read Script

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.

Affected products

Published 2017-12-20. Last modified 2026-06-17.