GHSA-wv4h-qxh7-5899LowCVSS 3.7

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and...

Published
July 31, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present.

🔗 References (3)