Description
The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its plan, status and expiration.
Published: 2026-08-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Paid Membership Subscriptions WordPress plugin versions prior to 3.0.8 fails to verify that a subscription being altered through the change‑subscription checkout belongs to the user who is currently logged in. As a result, an authenticated user with a Subscriber role or higher can modify another member’s subscription, overwriting the plan, status, and expiration. The flaw allows an attacker to impersonate another user, change billing details, and gain access to content or features they are not entitled to. This constitutes an improper access control weakness (CWE‑284).

Affected Systems

Any WordPress site using the Paid Membership Subscriptions plugin before version 3.0.8 is affected. The issue applies to the plugin as distributed by the vendor and is not limited to a specific host or WordPress installation. Administrators should verify the installed version on all sites that use this plugin.

Risk and Exploitability

The vulnerability requires the attacker to be authenticated with a Subscriber role or higher. Once logged in, the attacker can target any user’s subscription via the checkout flow, potentially altering financial and access controls. Because the flaw is client‑side from the user perspective but does not trigger an obvious alert, the risk is high, especially in environments where subscription data determines content access or billing. While no EPSS or KEV data is available, the lack of a verification step suggests an elevated risk of exploitation in active deployments.

Generated by OpenCVE AI on August 4, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Paid Membership Subscriptions plugin to version 3.0.8 or later.
  • Restrict the permission afforded to Subscriber‑level users so they cannot modify other users’ subscriptions via the checkout interface.
  • Audit subscription activity logs for unexpected changes to detect any ongoing hijacking attempts.

Generated by OpenCVE AI on August 4, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its plan, status and expiration.
Title Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T06:00:10.035Z

Reserved: 2026-07-06T11:38:59.458Z

Link: CVE-2026-14848

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:30:06Z

Weaknesses