Feed/CVE-2026-14848
CVE-2026-14848MEDIUMCVSS 5.4

CVE-2026-14848

Published Aug 4, 2026·Updated Aug 4, 2026

NVD Description

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above to take over another member's subscription and overwrite its plan, status and expiration.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free