CVE-2026-14847
Received Received - Intake

Unauthorized Payment Details Disclosure in Paid Memberships Pro WordPress Plugin

Vulnerability report for CVE-2026-14847, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
paid_membership_subscriptions paid_membership_subscriptions to 3.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) flaw in the Paid Membership Subscriptions WordPress plugin before version 3.0.7. It allows authenticated users with Subscriber-level access or higher to view sensitive payment details of other members by exploiting a lack of capability or nonce checks in a payment-related AJAX action.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Paid Membership Subscriptions plugin version prior to 3.0.7. Inspect network traffic for AJAX requests to payment-related endpoints and verify if payment details can be accessed without proper authentication or nonce checks.

Impact Analysis

An attacker could disclose payment details such as Payment ID, date, amount, currency, and payment gateway of any member by enumerating payment identifiers. This could lead to privacy breaches and potential misuse of financial information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive payment and personal data, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Immediately update the Paid Membership Subscriptions plugin to version 3.0.7 or later. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Review payment logs for unauthorized access and restrict Subscriber-level user permissions where possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14847. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart