Impact
The vulnerability resides in WordPress's Paid Membership Subscriptions plugin before version 3.0.7. The plugin’s payment‑related AJAX action fails to perform proper capability or nonce checks. As a result, any authenticated user with Subscriber level access or higher can enumerate payment identifiers and retrieve billing information belonging to other members. This flaw exposes sensitive financial data and compromises member confidentiality and the integrity of the payment system.
Affected Systems
Governments, businesses or any organization using the Paid Membership Subscriptions WordPress plugin on any site that has a version earlier than 3.0.7. The vulnerability is present across all environments that deploy the plugin without the specified update.
Risk and Exploitability
The likely attack vector requires an attacker to be logged into the site as a Subscriber or higher role. Once authenticated, the attacker can systematically request payment details by manipulating the payment identifier parameter in the AJAX call. The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog, which indicates a lower publicly known exploitation frequency. Nonetheless, the absence of nonce and capability checks creates a clear path for data disclosure, making the flaw high‑impact once the credential requirements are met.
OpenCVE Enrichment