Medium severity5.3NVD Advisory· Published Sep 23, 2026
CVE-2026-90950
CVE-2026-90950
Description
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.