CVE-2026-10820
Received
Received - Intake
Authenticated User Can Cancel Other Users' Subscriptions via IDOR
Publication date: 2026-06-27
Last updated on: 2026-06-27
Assigner: WPScan
Description
Description
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other users' active subscriptions via an Insecure Direct Object Reference.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| paid_membership_pro | paid_membership_plugin | to 4.16.17 (exc) |
| profilepress | profilepress | to 4.16.17 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |