Impact
The vulnerability is an unauthenticated authentication bypass in the Paid Member Subscriptions plugin up to version 3.0.9 for WordPress. The flaw allows an attacker to access or modify subscription settings and user data without providing valid credentials, thereby compromising the confidentiality and integrity of membership information. As this is a logical flaw, it could enable privilege escalation within the WordPress site if the subscription data is held high‑value or used to gate content.
Affected Systems
Vulnerable systems are WordPress installations that run the Cozmoslabs Paid Member Subscriptions plugin version 3.0.9 or older. The CNA lists the affected product as Cozmoslabs:Paid Member Subscriptions. No specific operating system or database versions are limited; the issue exists wherever the plugin is active.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact if exploited. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a widely known or actively exploited vulnerability. The flaw is exploitable via unauthenticated HTTP requests to the plugin’s internal endpoints, as the plugin fails to enforce proper authentication. Attackers would only need network access to the WordPress site and do not require privileged credentials. The lack of a public exploit makes the likelihood uncertain, but because the vulnerability permits credential‑less access, it represents a nontrivial risk to any site that uses the affected plugin.
OpenCVE Enrichment