VYPR

Paid Membership Subscriptions

by WordPress

CVEs (13)

  • CVE-2024-12919CriJan 14, 2025
    risk 0.57cvss 9.8epss 0.01

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the…

  • CVE-2024-10261HigNov 9, 2024
    risk 0.40cvss 7.3epss 0.00

    The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an…

  • CVE-2026-14848MedAug 4, 2026
    risk 0.35cvss 5.4epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another…

  • CVE-2026-90950MedSep 23, 2026
    risk 0.34cvss 5.3epss —

    The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.

  • CVE-2026-90922MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower…

  • CVE-2024-1389MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.01

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all…

  • CVE-2024-9222MedOct 2, 2024
    risk 0.33cvss 6.1epss 0.00

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and…

  • CVE-2026-14847MedJul 31, 2026
    risk 0.28cvss 4.3epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by…

  • CVE-2024-1390MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.01

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and…

  • CVE-2025-11835MedNov 5, 2025
    risk 0.27cvss 5.3epss 0.00

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation check on the PMS_AJAX_Checkout_Handler::process_payment()…

  • CVE-2024-11291MedDec 18, 2024
    risk 0.27cvss 5.3epss 0.00

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible…

  • CVE-2026-90951LowSep 23, 2026
    risk 0.24cvss 3.7epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.

  • CVE-2026-14849LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII)…