Sceawere
Vulnerability Detail
CVE-2026-97249UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Paid Member Subscriptions Unauthenticated Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Cozmoslabs
- Product
- Paid Member Subscriptions
- Attack Type
- CWE-290 Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-30T13:17:36.960Z",
"pubdate": "2026-09-30T13:17:36.960Z",
"executiveSummary": "The Paid Member Subscriptions plugin for WordPress, specifically versions 3.0.9 and earlier, contains an unauthenticated security bypass vulnerability. This flaw allows remote, unauthenticated attackers to circumvent access controls and interact with restricted site functionality.\nThe vulnerability type is classified as an authentication or access control bypass. The primary impact involves the unauthorized execution of functions that are intended to be protected by membership or administrative authentication requirements.\nThe flaw affects all installations of Paid Member Subscriptions up to and including version 3.0.9. The risk implication is significant, as it permits unauthorized actors to manipulate subscription states, potentially access restricted content, or perform actions reserved for authenticated users without possessing valid credentials.\nExploitation requires no prior authentication and can be performed over the network via standard HTTP requests. No special user interaction is required from legitimate administrators or members to facilitate the compromise. Given the nature of the plugin, which manages user roles and payment-gated content, successful exploitation threatens the integrity of the site's access management architecture and potentially the exposure of sensitive user or member-only information.",
"technicalDetails": "The vulnerability originates from an improper implementation of access control checks within the core logic of the Paid Member Subscriptions plugin. In versions 3.0.9 and below, the plugin fails to sufficiently validate the authentication state or the authorization level of the requester when processing specific input parameters or API endpoints designed for member management.\nThe root cause is likely an insufficient server-side verification of security tokens or user sessions during the dispatching of plugin-specific actions. When the application receives a request intended for a protected function, it relies on client-supplied data or incomplete nonce verification to determine the user's status. Because these checks are either missing, incorrectly configured, or bypassable through malformed requests, the plugin proceeds to execute sensitive logic even when the request lacks a legitimate session cookie or valid authorization header.\nThe attack flow proceeds as follows: First, the attacker identifies the vulnerable endpoints or action hooks registered by the Paid Member Subscriptions plugin. These are typically handled via the WordPress admin-ajax.php or REST API framework. Second, the attacker crafts a malicious HTTP request (typically GET or POST) targeting these endpoints, purposefully omitting legitimate authentication credentials. Third, by manipulating parameters that the plugin uses to identify the context of the requested action, the attacker coerces the plugin into treating the request as authorized. Finally, the server executes the requested action, which may include modifying user subscription status, bypassing content protection, or triggering administrative functions.\nBecause the plugin facilitates the gated access of content, the post-exploitation impact includes the potential for unauthorized privilege escalation, such as granting a guest user 'member' status. This allows the attacker to view restricted pages or access protected digital assets that should have remained behind the plugin's authorization wall. The lack of strict origin or nonce validation further allows for automated exploitation scripts to crawl and bypass restrictions across the entire WordPress installation. The vulnerability is highly exploitable remotely as it does not rely on complex memory corruption techniques, but rather leverages logical flaws in the plugin's security boundary implementation."
}