← WordPress Vulnerabilities
WordPress security by component

Paid Membership Subscriptions

Paid Membership Subscriptions adds membership plans, subscription management, and restricted content capabilities to WordPress websites.

Paid Membership Subscriptions (paid-membership-subscriptions) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 5.4.

Plugin slug: paid-membership-subscriptions

CVE-2026-14848: Subscribers can take over other members' subscriptions

Paid Membership Subscriptions before 3.0.8 changes a subscription through its checkout flow without verifying that the targeted subscription belongs to the current user. A Subscriber can supply another member's subscription identifier and overwrite its plan, status and expiration. The public advisory does not disclose the checkout endpoint, identifier parameter, update fields or ownership-check function.

PublishedAug 04, 2026
Known safe version3.0.8
Published vulnerabilities for paid-membership-subscriptions
Safe version
Aug 04, 2026 CVE-2026-14848
Subscribers can take over other members' subscriptions
Paid Membership Subscriptions before 3.0.8 changes a subscription through its checkout flow without verifying that the targeted subscription belongs to the current user. A Subscriber can supply another member's subscription identifier and overwrite its plan, status and expiration. The public advisory does not disclose the checkout endpoint, identifier parameter, update fields or ownership-check function.
3.0.8
CVE5.4
NVDPending
Jul 31, 2026 CVE-2026-14849
Paid Membership Subscriptions leaves exports publicly downloadable
Paid Membership Subscriptions before 3.0.7 writes member and payment export artifacts to a predictable location beneath the public uploads directory without access protection. While an export artifact exists, an unauthenticated visitor who requests its predictable URL can download member and payment data, including personally identifiable information. The published record does not disclose the exact directory, filename pattern, export action or cleanup interval.
3.0.7
CVE3.7
NVDPending
Jul 31, 2026 CVE-2026-14847
Paid Membership Subscriptions exposes any member's payment details to Subscribers
Paid Membership Subscriptions before 3.0.7 exposes a payment-related AJAX action without a capability or nonce check. Any authenticated Subscriber-or-higher user can enumerate payment identifiers and request payment details belonging to other members. The published record does not identify the AJAX action, payment-ID parameter, callback function or the exact payment fields returned.
3.0.7
CVE4.3
NVDPending