PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14847 Paid Membership Subscriptions CVE debrief

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier. This vulnerability affects WordPress sites using the Paid Membership Subscriptions plugin, particularly those with active user subscriptions. The issue arises from inadequate access controls on payment-related AJAX actions, enabling unauthorized disclosure of sensitive payment information.

Vendor
Paid Membership Subscriptions
Product
Paid Membership Subscriptions
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-07-31
Advisory published
2026-07-31
Advisory updated
2026-07-31

Who should care

Administrators of WordPress sites using the Paid Membership Subscriptions plugin, especially those with active user subscriptions, should be aware of this vulnerability and take immediate action to protect their sites and users' sensitive payment information. Site owners, security teams, and vulnerability management teams should prioritize patching or mitigating this vulnerability to prevent potential unauthorized disclosure of payment details. Additionally, users with access to payment-related features should be cautious of potential enumeration attacks. Managed Security Service Providers (MSSPs) and security consultants may also need to review and advise on the vulnerability's impact for their clients' WordPress installations. WordPress developers and security researchers should verify the vulnerability's scope and provide further insights to enhance defensive measures. Lastly, e-commerce site administrators and digital payment processors may need to assess the vulnerability's impact on their platforms and customers' data security. IT and security teams should coordinate on implementing compensating controls and monitoring for suspicious activity related to payment detail enumeration. Compliance and risk management teams should also be informed about the potential risks associated with this vulnerability. Lastly, developers and QA teams should review the vendor's patch and test its effectiveness in preventing similar vulnerabilities in the future. The vulnerability management process should include tracking exceptions, retesting remediated assets, and documenting evidence of successful mitigation. The security awareness training for developers and IT staff should emphasize secure coding practices and thorough testing of payment-related features to prevent similar issues in the future. The incident response plan should be updated to include procedures for responding to potential exploitation attempts and data breaches related to this vulnerability. The security information and event management (SIEM) system should be configured to detect and alert on suspicious activity related to payment detail enumeration. The vulnerability management team should prioritize 7

Technical summary

The Paid Membership Subscriptions WordPress plugin before 3.0.7 is vulnerable to unauthorized payment detail disclosure due to insufficient capability and nonce checks on its payment-related AJAX actions. Authenticated users with Subscriber-level access or higher can enumerate and access payment identifiers of other members. This vulnerability impacts sites with active user subscriptions, potentially exposing sensitive payment details to unauthorized users.

Defensive priority

Authenticated users with Subscriber-level access and above may be able to disclose payment details of other members.

Recommended defensive actions

  • Review and apply the vendor's patch to update the Paid Membership Subscriptions plugin to version 3.0.7 or later.
  • Restrict access to sensitive payment-related AJAX actions to prevent unauthorized disclosure.
  • Monitor for suspicious activity related to payment detail enumeration.
  • Verify that the Paid Membership Subscriptions plugin version is 3.0.7 or later.
  • Check for any unauthorized access to payment details in the system logs.
  • Perform a thorough review of the system for any potential security vulnerabilities.
  • Ensure that all user subscriptions are properly secured and monitored.

Evidence notes

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions. This issue allows any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier. Further review is needed to determine the full scope of affected systems and user impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:25.640Z and has not been modified since then.