Description
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Published: 2026-07-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Server‑Side Request Forgery (SSRF) flaw exists in Paid Member Subscriptions versions up to 3.0.4. The vulnerability allows an attacker to instruct the vulnerable WordPress installation to issue arbitrary HTTP or HTTPS requests to any target. This can enable attackers to access internal network services, exfiltrate sensitive data, or launch secondary attacks against systems reachable from the WordPress host. The weakness is identified as CWE‑918, which indicates that the application fails to properly validate or sandbox outbound network traffic.

Affected Systems

All installations of the Paid Member Subscriptions plugin from Cozmoslabs running version 3.0.4 or earlier are affected. No specific WordPress core or hosting platform versions are listed as impacted, so any WordPress site using the vulnerable plugin is at risk.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating high severity. No EPSS score is reported, so current exploitation probability is unknown, but the fact that the flaw is unauthenticated and requires no additional privileges makes it potentially attractive to adversaries. The vulnerability is not listed in the CISA KEV catalog, but it remains a significant risk due to the ease of exploitation and potential internal impact.

Generated by OpenCVE AI on July 2, 2026 at 15:19 UTC.

Remediation

Vendor Solution

Update the WordPress Paid Member Subscriptions Plugin to the latest available version (at least 3.0.5).


OpenCVE Recommended Actions

  • Upgrade the Paid Member Subscriptions plugin to version 3.0.5 or later.
  • If an immediate upgrade is not possible, restrict the server's outbound network by configuring firewall rules that block outgoing traffic from the WordPress web server to internal IP ranges.
  • Disable any unused or unnecessary network services on the WordPress host to reduce the attack surface and mitigate possible secondary exploitation attempts.

Generated by OpenCVE AI on July 2, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Cozmoslabs
Cozmoslabs paid Member Subscriptions
Wordpress
Wordpress wordpress
Vendors & Products Cozmoslabs
Cozmoslabs paid Member Subscriptions
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Title WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Cozmoslabs Paid Member Subscriptions
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:08:50.836Z

Reserved: 2026-06-24T12:45:24.971Z

Link: CVE-2026-57348

cve-icon Vulnrichment

Updated: 2026-07-02T14:08:47.454Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-02T15:30:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)