Description
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Premium Membership Access
Action: Patch Plugin
AI Analysis

Impact

The vulnerable version of the Paid Membership Subscriptions WordPress plugin accepts a payment amount and currency supplied by PayPal without verifying that they match the expected amount and currency for the selected membership level. As a result, an unauthenticated user can submit a payment that is lower than the intended price or that uses a different currency, yet the plugin still grants the user full paid‑membership privileges. This constitutes an authorization bypass that allows attackers to obtain premium account features without paying the correct fee.

Affected Systems

Any WordPress site that installs Paid Membership Subscriptions before version 3.0.9 is vulnerable. The problem applies to all installations regardless of site size, as long as the plugin is active and PayPal Standard is used for payments.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, but the EPSS score of less than 1% suggests that exploit attempts are unlikely to be widespread at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to submit a payment request to the site, which is a relatively low barrier, yet the lack of verification makes the attack path trivial. Because the flaw is purely an authorization error, a successful exploitation yields immediate and permanent access to privileged content or services associated with the paid membership.

Generated by OpenCVE AI on September 18, 2026 at 04:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Paid Membership Subscriptions to version 3.0.9 or later, which validates payment amount and currency before granting membership.
  • Disable or restrict the use of PayPal Standard for new membership purchases until the plugin is upgraded, or switch to another integration that performs proper checks.
  • Review and reinforce access controls for paid‑membership content to ensure that only confirmed, fully paid memberships can unlock premium features.

Generated by OpenCVE AI on September 18, 2026 at 04:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
Title Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:27:29.613Z

Reserved: 2026-09-14T11:10:38.769Z

Link: CVE-2026-90922

cve-icon Vulnrichment

Updated: 2026-09-17T12:10:46.259Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.320

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-90922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses