Impact
A flaw in the Paid Member Subscriptions plugin for WordPress allows an attacker to manipulate request parameters to read or modify data belonging to other users. The vulnerability is caused by incorrectly enforced access control checks that rely on user‑controlled keys, resulting in an authorization bypass. If exploited, an attacker could view or alter sensitive membership information, potentially compromising personal data and the integrity of the site.
Affected Systems
Cozmoslabs Pay‑Member‑Subscriptions plugin for WordPress, versions up to and including 2.16.8 .
Risk and Exploitability
The CVSS score of 6.5 classifies the bug as Medium severity, but the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would typically need to send crafted HTTP requests to expose privileged resources; the reach is limited to authenticated or unauthenticated users who can guess or enumerate object identifiers. If the site hosts sensitive membership data, the potential impact rises to unauthorized disclosure and possible falsification of records.
OpenCVE Enrichment