PatchSiren cyber security CVE debrief
CVE-2026-90922 Paid Membership Subscriptions CVE debrief
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. This vulnerability can lead to financial losses and reputational damage. Defenders should assess exposure and verify the version of the plugin to prevent potential abuse. Reviewing payment provider reports can help detect potential abuse, and monitoring for suspicious activity related to paid memberships is necessary.
- Vendor
- Paid Membership Subscriptions
- Product
- Paid Membership Subscriptions
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for WordPress installations with the Paid Membership Subscriptions plugin should assess exposure and verify the version of the plugin. They should also review payment provider reports to detect potential abuse and monitor for suspicious activity related to paid memberships. Additionally, defenders should prioritize verifying the version of the Paid Membership Subscriptions plugin and ensuring that it is updated to 3.0.9 or later.
Why it matters
The Paid Membership Subscriptions plugin vulnerability allows unauthenticated users to obtain paid memberships by paying arbitrary lower amounts, which can lead to financial losses and reputational damage.
- Defenders must verify the version of the Paid Membership Subscriptions plugin to prevent potential abuse
- Reviewing payment provider reports can help detect potential abuse
- Monitoring for suspicious activity related to paid memberships is necessary
Technical summary
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. This vulnerability can lead to financial losses and reputational damage. Defenders should assess exposure and verify the version of the plugin to prevent potential abuse. Reviewing payment provider reports can help detect potential abuse, and monitoring for suspicious activity related to paid memberships is necessary. The vulnerability can be exploited by unauthenticated users, and defenders should prioritize verifying the version
Defensive priority
Defenders should prioritize verifying the version of the Paid Membership Subscriptions plugin and ensuring that it is updated to 3.0.9 or later.
Recommended defensive actions
- Verify the version of the Paid Membership Subscriptions plugin and update to 3.0.9 or later.
- Review payment provider reports to detect potential abuse.
- Monitor for suspicious activity related to paid memberships.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- technicalSummary
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but the scope of affected versions and potential impact require further verification. The Paid Membership Subscriptions plugin vulnerability allows unauthenticated users to obtain paid memberships by paying arbitrary lower amounts. Defenders must verify the version of the Paid Membership Subscriptions plugin and ensure that it is updated to 3.0.9 or later. Reviewing payment provider reports can help detect potential abuse, and monitoring for suspicious activity is a
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90922 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90922
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90922 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90922
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/a7f3882a-81d7-4915-b83c-10480eba493a/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.