CVE-2017-17777: Paid To Read Script Project Paid To Read Script
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.
Affected products
- Paid To Read Script Project Paid To Read Script: version 2.0.5 only
Published 2017-12-20. Last modified 2026-06-17.