Impact
The vulnerability allows an attacker who is already authenticated with a subscriber or higher role to trigger the 'ims_add_paypal_recurring_membership' AJAX action. Because the plugin fails to verify authorization, the action creates a fake PayPal receipt and grants the user an unrestricted premium membership tier. This results in unauthorized access to restricted property listings and increased allowance, i.e. privilege escalation, as defined by CWE‑862.
Affected Systems
The affected software is the WordPress plugin InspiryThemes RealHomes Memberships, versions 3.0.9 and all earlier releases. WordPress sites using these plugin versions are susceptible.
Risk and Exploitability
The CVSS score is 4.3, indicating low overall severity, and the EPSS score is below 1 %, implying that exploitation is improbable at present. The vulnerability is not listed in CISA KEV. An attacker requires only an existing authenticated account with subscriber‑level access to exploit the flaw, which can be achieved through normal account use; thus the attack vector is likely local to the site but does not require remote code execution.
OpenCVE Enrichment