Paid Membership Subscriptions
Paid Membership Subscriptions adds membership plans, subscription management, and restricted content capabilities to WordPress websites.
Paid Membership Subscriptions (paid-membership-subscriptions) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 5.4.
paid-membership-subscriptionsCVE-2026-14848: Subscribers can take over other members' subscriptions
Paid Membership Subscriptions before 3.0.8 changes a subscription through its checkout flow without verifying that the targeted subscription belongs to the current user. A Subscriber can supply another member's subscription identifier and overwrite its plan, status and expiration. The public advisory does not disclose the checkout endpoint, identifier parameter, update fields or ownership-check function.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-14848
Subscribers can take over other members' subscriptions
Paid Membership Subscriptions before 3.0.8 changes a subscription through its checkout flow without verifying that the targeted subscription belongs to the current user. A Subscriber can supply another member's subscription identifier and overwrite its plan, status and expiration. The public advisory does not disclose the checkout endpoint, identifier parameter, update fields or ownership-check function.
|
3.0.8 |
CVE5.4
NVDPending
|
| Jul 31, 2026 |
CVE-2026-14849
Paid Membership Subscriptions leaves exports publicly downloadable
Paid Membership Subscriptions before 3.0.7 writes member and payment export artifacts to a predictable location beneath the public uploads directory without access protection. While an export artifact exists, an unauthenticated visitor who requests its predictable URL can download member and payment data, including personally identifiable information. The published record does not disclose the exact directory, filename pattern, export action or cleanup interval.
|
3.0.7 |
CVE3.7
NVDPending
|
| Jul 31, 2026 |
CVE-2026-14847
Paid Membership Subscriptions exposes any member's payment details to Subscribers
Paid Membership Subscriptions before 3.0.7 exposes a payment-related AJAX action without a capability or nonce check. Any authenticated Subscriber-or-higher user can enumerate payment identifiers and request payment details belonging to other members. The published record does not identify the AJAX action, payment-ID parameter, callback function or the exact payment fields returned.
|
3.0.7 |
CVE4.3
NVDPending
|