The Paid Memberships Pro plugin for WordPress, which is used to restrict access to content, courses, and communities, had a vulnerability up to version 2.5.2. This vulnerability made it possible for attackers to download order data for other users due to incorrect user validation and capability checking on the pmpro_get_order_json() function.