Impact
The Paid Membership Subscriptions WordPress plugin before version 3.0.7 writes member and payment export files to a predictable location within the uploads directory without enforcing access controls, allowing any unauthenticated user to download these files while they exist. This vulnerability enables an attacker to obtain personally identifiable information (PII) and payment data, leading to potential privacy violations, fraud, or further exploitation. The weakness is a classic information disclosure flaw (CWE‑200).
Affected Systems
This issue affects the Paid Membership Subscriptions plugin for WordPress. Clients using any version earlier than 3.0.7 are vulnerable. The affected vendor is not identified in the CNA data; however, the plugin name and version constraints are clear.
Risk and Exploitability
The vulnerability is exploitable over the web by simply requesting the export file’s URL, which does not require authentication or privileged access. EPSS data is unavailable, and the issue is not listed in CISA KEV. Nevertheless, the potential impact of exposing PII is significant, and the straightforward attack vector makes it a high‑value target for adversaries. Upgrading to the fixed version mitigates the risk entirely.
OpenCVE Enrichment