PT-2026-53044 · WordPress · Paid Membership Plugin

·

CVE-2026-10820

·

Published

2026-06-27

·

Updated

2026-06-29

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content versions prior to 4.16.17
Description An Insecure Direct Object Reference occurs because the software fails to verify if the authenticated user performing a subscription action is the actual owner of the targeted subscription. This allows any user with Subscriber level permissions or higher to cancel active subscriptions belonging to other users.
Recommendations Update Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content to version 4.16.17 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10820

Affected Products

Paid Membership Plugin