Impact
The Paid Membership Subscriptions WordPress plugin versions prior to 3.0.8 fails to verify that a subscription being altered through the change‑subscription checkout belongs to the user who is currently logged in. As a result, an authenticated user with a Subscriber role or higher can modify another member’s subscription, overwriting the plan, status, and expiration. The flaw allows an attacker to impersonate another user, change billing details, and gain access to content or features they are not entitled to. This constitutes an improper access control weakness (CWE‑284).
Affected Systems
Any WordPress site using the Paid Membership Subscriptions plugin before version 3.0.8 is affected. The issue applies to the plugin as distributed by the vendor and is not limited to a specific host or WordPress installation. Administrators should verify the installed version on all sites that use this plugin.
Risk and Exploitability
The vulnerability requires the attacker to be authenticated with a Subscriber role or higher. Once logged in, the attacker can target any user’s subscription via the checkout flow, potentially altering financial and access controls. Because the flaw is client‑side from the user perspective but does not trigger an obvious alert, the risk is high, especially in environments where subscription data determines content access or billing. While no EPSS or KEV data is available, the lack of a verification step suggests an elevated risk of exploitation in active deployments.
OpenCVE Enrichment