PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90922 Paid Membership Subscriptions CVE debrief

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. This vulnerability can lead to financial losses and reputational damage. Defenders should assess exposure and verify the version of the plugin to prevent potential abuse. Reviewing payment provider reports can help detect potential abuse, and monitoring for suspicious activity related to paid memberships is necessary.

Vendor
Paid Membership Subscriptions
Product
Paid Membership Subscriptions
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress installations with the Paid Membership Subscriptions plugin should assess exposure and verify the version of the plugin. They should also review payment provider reports to detect potential abuse and monitor for suspicious activity related to paid memberships. Additionally, defenders should prioritize verifying the version of the Paid Membership Subscriptions plugin and ensuring that it is updated to 3.0.9 or later.

Why it matters

The Paid Membership Subscriptions plugin vulnerability allows unauthenticated users to obtain paid memberships by paying arbitrary lower amounts, which can lead to financial losses and reputational damage.

  • Defenders must verify the version of the Paid Membership Subscriptions plugin to prevent potential abuse
  • Reviewing payment provider reports can help detect potential abuse
  • Monitoring for suspicious activity related to paid memberships is necessary

Technical summary

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. This vulnerability can lead to financial losses and reputational damage. Defenders should assess exposure and verify the version of the plugin to prevent potential abuse. Reviewing payment provider reports can help detect potential abuse, and monitoring for suspicious activity related to paid memberships is necessary. The vulnerability can be exploited by unauthenticated users, and defenders should prioritize verifying the version

Defensive priority

Defenders should prioritize verifying the version of the Paid Membership Subscriptions plugin and ensuring that it is updated to 3.0.9 or later.

Recommended defensive actions

  • Verify the version of the Paid Membership Subscriptions plugin and update to 3.0.9 or later.
  • Review payment provider reports to detect potential abuse.
  • Monitor for suspicious activity related to paid memberships.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • technicalSummary

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, but the scope of affected versions and potential impact require further verification. The Paid Membership Subscriptions plugin vulnerability allows unauthenticated users to obtain paid memberships by paying arbitrary lower amounts. Defenders must verify the version of the Paid Membership Subscriptions plugin and ensure that it is updated to 3.0.9 or later. Reviewing payment provider reports can help detect potential abuse, and monitoring for suspicious activity is a

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90922 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90922

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90922 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90922

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.