Authentication vulnerability in Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction 2.13.7

A plugin called “Paid Membership Subscriptions” for WordPress has a security issue that could allow unauthorized access to user accounts. This affects all versions of the plugin up to 2.13.7. The problem is that the function responsible for redirecting payments does not properly check the user’s identity, allowing someone with a valid payment ID to log in as any user who has made a purchase on the website. This means that an attacker could gain access to sensitive information without needing to provide any credentials.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.