PT-2026-66704 · WordPress · Paid Membership Subscriptions

·

CVE-2026-14849

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Paid Membership Subscriptions versions prior to 3.0.7
Description The plugin fails to protect member and payment export files stored in a predictable location within the uploads directory. This allows unauthenticated users to download exported member and payment data, which may include personally identifiable information (PII), whenever an export artifact is present.
Recommendations Update to version 3.0.7 or later.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14849

Affected Products

Paid Membership Subscriptions