CVE-2026-90951 PUBLISHED

Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_payment

Assigner: WPScan
Reserved: 14.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.

Product Status

Vendor Unknown
Product Paid Membership Subscriptions
Versions Default: unaffected
  • affected from 0 to 3.1.0 (excl.)

Credits

  • vuxvinh finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE