PT-2026-53044 · WordPress · Paid Membership Plugin
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content versions prior to 4.16.17
Description
An Insecure Direct Object Reference occurs because the software fails to verify if the authenticated user performing a subscription action is the actual owner of the targeted subscription. This allows any user with Subscriber level permissions or higher to cancel active subscriptions belonging to other users.
Recommendations
Update Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content to version 4.16.17 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Paid Membership Plugin