Description
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
Published: 2026-07-31
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Paid Membership Subscriptions WordPress plugin before version 3.0.7 writes member and payment export files to a predictable location within the uploads directory without enforcing access controls, allowing any unauthenticated user to download these files while they exist. This vulnerability enables an attacker to obtain personally identifiable information (PII) and payment data, leading to potential privacy violations, fraud, or further exploitation. The weakness is a classic information disclosure flaw (CWE‑200).

Affected Systems

This issue affects the Paid Membership Subscriptions plugin for WordPress. Clients using any version earlier than 3.0.7 are vulnerable. The affected vendor is not identified in the CNA data; however, the plugin name and version constraints are clear.

Risk and Exploitability

The vulnerability is exploitable over the web by simply requesting the export file’s URL, which does not require authentication or privileged access. EPSS data is unavailable, and the issue is not listed in CISA KEV. Nevertheless, the potential impact of exposing PII is significant, and the straightforward attack vector makes it a high‑value target for adversaries. Upgrading to the fixed version mitigates the risk entirely.

Generated by OpenCVE AI on July 31, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Paid Membership Subscriptions plugin to version 3.0.7 or later.
  • If an immediate upgrade is not feasible, disable the export feature or remove any residual export files from the uploads directory while awaiting a patch.
  • Configure the site to restrict direct access to the uploads directory, or move the export files to non‑public storage locations to prevent unauthenticated downloads.

Generated by OpenCVE AI on July 31, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-552
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.
Title Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T13:25:56.328Z

Reserved: 2026-07-06T11:39:00.960Z

Link: CVE-2026-14849

cve-icon Vulnrichment

Updated: 2026-07-31T13:25:42.438Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T19:00:10Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties