Description
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create pricing tables.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17147 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create pricing tables. |
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via creating_pricing_table_page |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cozmoslabs
Cozmoslabs membership \& Content Restriction - Paid Member Subscriptions |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:cozmoslabs:membership_\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Cozmoslabs
Cozmoslabs membership \& Content Restriction - Paid Member Subscriptions |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:36:10.077Z
Reserved: 2024-02-08T22:16:32.856Z
Link: CVE-2024-1390
Updated: 2024-08-01T18:40:20.369Z
Status : Modified
Published: 2024-02-29T01:43:49.500
Modified: 2026-04-08T17:18:19.967
Link: CVE-2024-1390
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD