Description
The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves any premium membership tier without completing a PayPal transaction, generating a falsified active payment receipt and gaining unauthorized access to restricted property listing allowances.
Published: 2026-08-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who is already authenticated with a subscriber or higher role to trigger the 'ims_add_paypal_recurring_membership' AJAX action. Because the plugin fails to verify authorization, the action creates a fake PayPal receipt and grants the user an unrestricted premium membership tier. This results in unauthorized access to restricted property listings and increased allowance, i.e. privilege escalation, as defined by CWE‑862.

Affected Systems

The affected software is the WordPress plugin InspiryThemes RealHomes Memberships, versions 3.0.9 and all earlier releases. WordPress sites using these plugin versions are susceptible.

Risk and Exploitability

The CVSS score is 4.3, indicating low overall severity, and the EPSS score is below 1 %, implying that exploitation is improbable at present. The vulnerability is not listed in CISA KEV. An attacker requires only an existing authenticated account with subscriber‑level access to exploit the flaw, which can be achieved through normal account use; thus the attack vector is likely local to the site but does not require remote code execution.

Generated by OpenCVE AI on August 2, 2026 at 03:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RealHomes Memberships to the latest version that includes the authorization check for the payment action.
  • If immediate upgrading is not possible, restrict or block the 'ims_add_paypal_recurring_membership' AJAX endpoint so it can only be accessed by administrators.
  • Disable the RealHomes Memberships plugin on non‑production environments while additional protective measures are implemented.

Generated by OpenCVE AI on August 2, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Inspirythemes
Inspirythemes realhomes Memberships
Wordpress
Wordpress wordpress
Vendors & Products Inspirythemes
Inspirythemes realhomes Memberships
Wordpress
Wordpress wordpress

Sat, 01 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves any premium membership tier without completing a PayPal transaction, generating a falsified active payment receipt and gaining unauthorized access to restricted property listing allowances.
Title RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass via 'ims_add_paypal_recurring_membership' AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Inspirythemes Realhomes Memberships
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-03T19:21:36.912Z

Reserved: 2026-06-03T16:03:47.830Z

Link: CVE-2026-10782

cve-icon Vulnrichment

Updated: 2026-08-03T19:21:33.028Z

cve-icon NVD

Status : Deferred

Published: 2026-08-01T09:16:58.300

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-10782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:01Z

Weaknesses