GHSA-wv4h-qxh7-5899LowCVSS 3.7
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and...
🔗 CVE IDs covered (1)
📋 Description
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.