CVE-2026-19709
Received Received - Intake

Membership Data Exposure in WooCommerce Plugin

Vulnerability report for CVE-2026-19709, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: WPScan

Description

The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
membership_for_woocommerce membership_for_woocommerce to 3.1.2 (exc)
woocommerce membership_for_woocommerce to 3.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass flaw in the Membership For WooCommerce WordPress plugin before version 3.1.2. It allows unauthenticated attackers to access REST routes by exploiting a flaw in the consumer secret verification process. The plugin does not check if an API consumer secret was generated before comparing it with the one provided in a request.

Detection Guidance

Check the installed version of the Membership For WooCommerce plugin using WordPress admin panel or via command line with: wp plugin list --name=membership-for-woocommerce. If the version is below 3.1.2, the system is vulnerable.

Impact Analysis

This vulnerability enables attackers to disclose sensitive membership plan details of any user on sites where the API is enabled but no keys were ever created. It allows unauthenticated access to restricted data, potentially exposing private user information.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR and HIPAA by exposing sensitive user data. Unauthorized access to membership details may violate privacy requirements and result in legal or regulatory penalties.

Mitigation Strategies

Update the Membership For WooCommerce plugin to version 3.1.2 or later immediately. Disable the plugin's REST API if not required or restrict access to authenticated users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19709. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart