Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105317 | 2 Cozmoslabs, Wordpress-extensions | 2 Paid Member Subscriptions, Paid Member Subscriptions | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | ||||
| CVE-2026-90951 | 1 Wordpress-extensions | 1 Paid Member Subscriptions | 2026-09-28 | 3.7 Low |
| The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. | ||||
| CVE-2026-90950 | 1 Wordpress-extensions | 1 Paid Member Subscriptions | 2026-09-28 | 5.3 Medium |
| The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled. | ||||
Page 1 of 1.