Impact
The vulnerability is a subscriber bypass flaw in the MicroPayments plugin, allowing a user to access paid content without authenticating as a paying subscriber. This logic error can lead to unauthorized users obtaining benefits intended for paid members, potentially compromising revenue streams and violating access controls. The weakness is identified as CWE-1284, a logic or flow control issue that undermines entitlement checks.
Affected Systems
The affected product is the MicroPayments – Fans Paysite / Paid Membership plugin from videowhisper, in all releases up to and including version 3.2.9. Users running any of these versions are at risk; versions 3.2.10 and newer contain the fix.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of the plugin, where an attacker may craft a request that circumvents the subscription check. Successful exploitation would grant the attacker access to paid-only content without payment.
OpenCVE Enrichment