Critical severity9.8NVD Advisory· Published Jan 14, 2025· Updated Jun 17, 2026
CVE-2024-12919
CVE-2024-12919
Description
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:cozmoslabs:membership_\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:cozmoslabs:membership_\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:*range: <2.13.8
- (no CPE)range: 0
<=2.13.7+ 1 more
- (no CPE)range: <=2.13.7
- (no CPE)
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.