Recently a member of the community has pointed out a potential security issue in the subscriptions module.
Though I am glad to say I havn't had any reports of this being abbused it is strongly recomended that you upgrade to the latest release of 2.2.1
The issue that has been fixed:
When a user goes to your PayPal success page it will now properly varify that it is a PayPal transaction.
Not only will it verify but it wil check for any errors and stop the proccess from happening.
In the event that it finds any errors or fraud attemps it will stop, display an error message and send the admin an email with all IP information and errors it encounered.
When you upgrade make sure you have IPN set to on in your PayPal account and don't use Auto Return.
If their are any issues please post them here http://www.skpdev.net
Posted by scetter on Tuesday, August 22, 2006 (14:18:41) (2144 reads)