Impact
The RealHomes Memberships WordPress plugin before version 3.1.0 fails to confirm that a payment has been processed, to validate a nonce, or to assess the user’s capability prior to assigning a paid membership. Consequently an authenticated user such as a Subscriber can acquire paid membership packages without completing the required payment, representing an authorization bypass flaw.
Affected Systems
All WordPress sites that use the RealHomes Memberships plugin and are installed with a version earlier than 3.1.0 are affected. The issue is present regardless of the site’s configuration, impacting any user who is authenticated to the REST or admin interface of the plugin.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Exploitation requires only that the attacker be an authenticated user with a role that can interact with the membership endpoint, a condition that is widely satisfied on most sites. Because the EPSS score is lacking and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of widespread automated attacks is currently low, but the potential for manual misuse exists and may lead to financial losses or unauthorized access to premium content.
OpenCVE Enrichment