Sceawere

Vulnerability Detail

CVE-2026-15246UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RealHomes Memberships Payment Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
Unknown
Product
RealHomes Memberships
Attack Type
CWE-345 Insufficient Verification of Data Authenticity
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-06T15:16:43.523Z",
  "pubdate": "2026-08-06T15:16:43.523Z",
  "executiveSummary": "The RealHomes Memberships WordPress plugin prior to version 3.1.0 suffers from an authorization and validation vulnerability that enables authenticated users, such as those with minimal privileges like Subscribers, to acquire paid membership packages without completing the underlying financial transaction.\nThe core vulnerability stems from the application failing to verify whether a membership payment has successfully completed, alongside a complete lack of nonce validation and user capability checks.\nThis flaw exposes the affected product to broken access control and improper authorization risks.\nAn attacker possessing low-privileged authenticated access can directly interact with the membership processing functionality to assign themselves high-tier paid packages without authorization.\nThe business impact includes unauthorized access to premium features, potential financial loss due to bypassed payment gateways, and unauthorized privilege escalation within the context of the membership system.\nExploitation requires network access to the target WordPress instance and an active, authenticated low-privileged session, but does not necessitate interaction from a higher-privileged administrator or successful payment gateway callbacks.",
  "technicalDetails": "The vulnerability resides within the membership acquisition and processing logic of the RealHomes Memberships WordPress plugin for versions before 3.1.0.\nThe root cause of the issue is a triad of missing security controls: the absolute lack of payment verification to confirm transaction completion, the absence of cryptographic nonce checks to prevent cross-site request forgery and unauthorized direct invocation, and the omission of capability checks (such as current_user_can) to validate whether the initiating user possesses the administrative or specific role permissions required to modify membership states.\nThe vulnerable component processes membership package assignments insecurely upon user request.\nBecause access controls are entirely absent or improperly implemented, any authenticated user—including the default Subscriber role—can issue requests designed to trigger the membership assignment mechanism.\nThe attack flow proceeds as follows: First, an authenticated attacker with Subscriber-level privileges initiates a request targeting the membership processing routine. Second, because the backend logic omits capability verification, the application accepts the request from the low-privileged user. Third, the software bypasses interaction with external payment processors or fails to query the payment gateway API to verify transaction settlement. Fourth, the application immediately grants the requested paid membership package to the user's account.\nNetwork exposure is defined by the standard HTTP/HTTPS accessibility of the WordPress installation running the vulnerable plugin.\nThe attack requires authentication, lowering the barrier to entry since open user registration typically allows attackers to provision their own Subscriber accounts.\nPost-exploitation impact includes unauthorized acquisition of premium digital goods, subscription tiers, and access restricted to paid members, fundamentally subverting the monetization and access control boundaries enforced by the platform."
}
CVE-2026-15246: RealHomes Memberships Payment Bypass Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere